AE-BNQTVDWF
Code agent's local Python executor sandbox is escaped through whitelisted modules and functions, giving arbitrary code execution
SECURITY FAILUREseverity: CRITICALcause: LIKELYoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM
smolagents' local_python_executor.py, which runs agent-generated Python in a restricted environment, could be bypassed: attackers could use whitelisted modules and functions to execute arbitrary code on the host despite static and dynamic checks. The project fixed it by preventing access to submodules through indirect attribute access.
- Framework / agent
- smolagents · code-writing agent (CodeAgent) executing model-generated Python
- Remediation attempts
- TESTED
- Recurrence
- not documented
- Source languages
- en, und-Latn
- Updated
- 2026-09-29
Sources
- SECURITY ADVISORY smolagents has Sandbox Escape Vulnerability in the local_python_executor.py Module — github.com/advisories, retrieved 2026-09-29
- GITHUB COMMIT Prevent submodules through indirect attribute access in LocalPythonExecutor (#1375) — github.com/huggingface/smolagents, retrieved 2026-09-29
Symptoms
- Code executed by the restricted local Python executor escapes the sandbox and runs arbitrary code on the host
- The isolation boundary for untrusted code is broken, risking data leakage and system compromise
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-BNQTVDWF. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.