PT-2026-39004 · Praisonai · Praisonai

·

CVE-2026-44337

·

Published

2026-05-08

·

Updated

2026-07-13

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions PraisonAI versions 2.4.1 through 4.6.33
Description PraisonAI is a multi-agent teams system that exposes optional SQL/CQL-backed knowledge-store implementations. These implementations build table and index identifiers using unvalidated name and collection arguments. Applications passing untrusted collection names into these backends can trigger SQL or CQL injection, which occurs when malicious SQL or CQL statements are inserted into entry fields for execution.
Recommendations Update to version 4.6.34.

Exploit

Fix

SQL injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44337
GHSA-3643-7V76-5CJ2
PYSEC-2026-2897

Affected Products

Praisonai