PT-2026-29826 · Praisonai · Praisonai

Yerang30

·

Published

2026-04-01

·

Updated

2026-04-03

·

CVE-2026-34939

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PraisonAI versions prior to 4.5.90
Description PraisonAI's MCPToolIndex.search tools() function compiles a caller-supplied string directly as a Python regular expression without validation, sanitization, or a timeout. A crafted regular expression can cause catastrophic backtracking in the re engine, blocking the Python thread for hundreds of seconds and leading to a complete service outage. The function search tools() takes a query directly from the caller without validation and compiles it using re.compile(). This compiled pattern is then used to search tool names and hints. The issue is located in tool index.py lines 365 to 368.
Recommendations Update PraisonAI to version 4.5.90 or later.

Fix

DoS

Weakness Enumeration

Related Identifiers

CVE-2026-34939
GHSA-8W9J-HC3G-3G7F

Affected Products

Praisonai