PT-2026-30455 · Premai Io · Premsql

Goku

·

Published

2026-04-05

·

Updated

2026-04-05

·

CVE-2026-5594

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions premAI-io premsql versions up to 0.2.1
Description A weakness exists in the eval function within the premsql/agents/baseline/workers/followup.py file of premAI-io premsql. Manipulation of the result argument can lead to code injection, potentially allowing for remote attacks. The exploit has been publicly released.
Recommendations Update premsql to a version later than 0.2.1.

Exploit

Fix

Code Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5594

Affected Products

Premsql