highCVSS 7.6Vulnerability

GHSA-gqmf-56h7-rrpf

## Summary The published npm package `praisonai` exports a TypeScript `SandboxExecutor` with a `network-isolated` mode. The CLI lists that mode as: ```text network-isolated No network access (proxy blocked) ``` The implementation does not create a network namespace, firewall rule, socket filter, or proxy-enforced execution boundary. It only injects proxy environment variables into the child process: ```ts http_proxy: 'http://localhost:0', https_proxy: 'http://localhost:0', HTTP_PROXY: 'http://localhost:0', HTTPS_PROXY: 'http://localhost:0', no_proxy: '', NO_PROXY: '' ``` Clients that do not explicitly honor those proxy variables continue to use the host network stack. A local-only PoV shows that, inside `mode: "network-isolated"`, a proxy-aware Node invocation is stopped, while a plain Node HTTP client reaches a loopback HTTP server from the same sandboxed command environment. This is a network-isolation protection failure in an exported npm API and CLI mode. It is not a generic claim that every PraisonAI sandbox backend is affected. ## Technical Details `src/praisonai-ts/src/cli/features/sandbox-executor.ts` declares the mode: ```ts export type SandboxMode = 'disabled' | 'basic' | 'strict' | 'network-isolated'; ``` `SandboxExecutor.spawn()` starts the command through the host shell and passes only the environment returned by `buildEnv()`: ```ts const proc = spawn('sh', ['-c', command], { cwd: this.config.cwd, env, timeout: this.config.timeout, stdio: ['pipe', 'pipe', 'pipe'] }); ``` For `network-isolated`, `buildEnv()` does not apply an OS-level network restriction. It only sets proxy variables: ```ts case 'network-isolated': // No network access (requires additional OS-level setup) return { ...baseEnv, http_proxy: 'http://localhost:0', https_proxy: 'http://localhost:0', HTTP_PROXY: 'http://localhost:0', HTTPS_PROXY: 'http://localhost:0', no_proxy: '', NO_PROXY: '' }; ``` The CLI mode listing presents this as

Properties

ghsa_id
GHSA-gqmf-56h7-rrpf
summary
npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
severity
high
cvss_score
7.6
cve_id
GHSA-gqmf-56h7-rrpf
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
is_ghsa_only
true
ghsa_published
2026-06-18T14:26:28Z
source_url
https://github.com/advisories/GHSA-gqmf-56h7-rrpf
ghsa_updated
2026-06-18T14:26:30Z

Related Entities (5)

AFFECTS (1)

[Software]npm/praisonai

HAS_WEAKNESS (2)

[Weakness]Improper Isolation or Compartmentalization
[Weakness]Protection Mechanism Failure

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/praisonai

Explore deeper with Ninja Signal's threat intelligence graph