CVE-2026-57135 is a sandbox isolation flaw in the PraisonAI npm package praisonai affecting SandboxExecutor's network-isolated mode. The mode is advertised as preventing network access, but it does not enforce network isolation at the operating-system level. Instead, the protection can be bypassed by network clients that do not honor proxy-based restrictions. As a result, commands executed inside the sandbox may still establish outbound or local network connections despite the expected no-network boundary. The issue is a security-control failure rather than a memory-corruption bug, and it undermines assumptions that sandboxed execution is isolated from external or internal network resources.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
network-isolated mode as a trustworthy security boundary until OS-level enforcement is in place. Restrict outbound connectivity at the host, container, or network layer using default-deny egress controls and explicit allowlists where necessary. Avoid exposing sandboxed command execution to untrusted user or prompt-controlled input when operation depends on an assumption of no network access. Additional compensating controls include isolating workloads from sensitive internal services and metadata endpoints.Patch, then assume compromise.
praisonai package to version 1.7.2 or later. A complete remediation requires enforcing network denial with operating-system or platform controls rather than relying on application-level proxy behavior. Appropriate approaches include network namespaces, firewall policy, sandbox profiles, container or virtual-machine isolation, or socket-filtering mechanisms. If true network isolation is not implemented, the feature should not be represented as a security boundary.No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.