PraisonAI CodeAgent: LLM-Generated Code Runs Unsandboxed with Full Environment Access, Enabling Secret Theft via Prompt Injection
What happened
A GitHub Security Advisory (GHSA-2xv2-w8cq-5gxw, tracked as CVE-2026-61447) discloses that CodeAgent._execute_python() in the praisonaiagents Python package runs LLM-generated code in a subprocess seeded with a full copy of the parent process environment (os.environ.copy()). According to the advisory, there is no AST validation, no import restrictions, and no enforcement of the CodeConfig(sandbox=True) setting — the sandbox flag is reportedly dead code. A public proof-of-concept is included showing the agent printing environment variables matching patterns like KEY, SECRET, TOKEN, and PASSWORD. CVSS is listed at 10.0.
Why it matters
CodeAgent is designed to execute code the LLM itself writes, often in response to user input, tool output, or ingested content. If an attacker can influence what the model generates — classic prompt injection — the advisory describes a direct path to reading every secret in the process environment (API keys, database credentials, cloud tokens) and to arbitrary code execution with no import or syscall restrictions. Any application embedding this agent with real credentials in its environment is affected, and the exposure is remotely triggerable through any untrusted content the agent processes, not just direct operator input.
What to watch for / do now
- Treat any environment variable available to a
CodeAgent-hosting process as exposed; avoid injecting production secrets into processes that invoke LLM code execution. - If using
praisonaiagents, check your installed version against the fix referenced in the advisory and update once a patched release is available. - Where upgrading isn't immediately possible, consider running CodeAgent execution in an isolated process/container with a minimal, scoped environment (no inherited secrets) rather than relying on the library's built-in sandbox flag.
- Hunt for anomalous outbound network calls or environment-variable enumeration originating from agent code-execution subprocesses, and review any pipeline where untrusted text (tool results, documents, web content) reaches an LLM that can trigger code execution.
- Audit prompts and tool-result handling for injection resistance, since this flaw is only reachable through content that influences LLM output.
Developing intel
This is a same-day advisory disclosure with a public PoC and no confirmed in-the-wild exploitation reported yet; details may evolve as the maintainers respond. See the original advisory for the latest: GHSA-2xv2-w8cq-5gxw.