VYPR
Critical severity9.9GHSA Advisory· Published Jul 21, 2026· Updated Jul 21, 2026

CVE-2026-47392

CVE-2026-47392

Description

PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, execute_code() in praisonaiagents/tools/python_tools.py (v1.6.37, subprocess sandbox mode) can be fully bypassed using print.__self__ to retrieve the real Python builtins module, from which __import__ can be extracted via vars() and runtime string construction. This achieves arbitrary OS command execution on the host, completely defeating the sandbox. This is a novel bypass that survives all patches for CVE-2026-39888 (frame traversal), CVE-2026-34938 (str subclass), and CVE-2026-40158 (type.__getattribute__ trampoline). PraisonAI version 4.6.40 and praisonaiagents version 1.6.40 contain an updated fix.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
praisonaiagentsPyPI
< 1.6.401.6.40
PraisonAIPyPI
< 4.6.404.6.40

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

1