AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-60085.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 8.7CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 08, 2026

Disclosure summary

Summary SecurityPolicy in praisonaiagents/sandbox/config.py is a documented configuration data class with fields for allow_subprocess, allowed_paths, blocked_paths, allowed_commands, blocked_commands, allowed_imports, and blocked_imports. Its strict() classmethod is explicitly described as creating "a strict security policy for untrusted code," setting allow_subprocess=False and allow_file_write=False, and inheriting default blocked_paths (/etc/passwd, /etc/shadow, ~/.ssh, ~/.aws, ~/.config) and blocked_commands (rm -rf, dd, mkfs, fdisk, shutdown, reboot). The default sandbox backend, Subprocess Sandbox (praisonai/sandbox/subprocess.py), implements code/command execution by writing input to a temp file and invoking it via asyncio.create_subprocess_exec() directly, with no checking of any kind against blocked_commands, blocked_imports, blocked_paths, allow_subprocess, or allow_file_write. A search across every sandbox backend file in the repository confirms these fields are referenced nowhere outside the data class that declares them. Only allow_network and max_output_size are actually consulted. Verification Using a Security Policy.strict()-configured Sandbox Config(sandbox_type="s

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-5r6c-gj4g-r697

Open original source · Updated Oct 08, 2026

PraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend

Source severity: HIGH / 8.7

EcosystemPackageAffected rangeFirst patched
pippraisonai4.6.78

Original records & references

PUBLISHED 2026-10-08T17:58:11-04:00
MODIFIED 2026-10-08T17:58:12-04:00
INGESTED 2026-10-10T20:25:14-04:00