PT-2026-39004 · Praisonai · Praisonai

Shmulc8

·

Published

2026-05-08

·

Updated

2026-05-11

·

CVE-2026-44337

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions PraisonAI versions 2.4.1 through 4.6.33
Description PraisonAI is a multi-agent teams system that exposes optional SQL/CQL-backed knowledge-store implementations. These implementations build table and index identifiers using unvalidated name and collection arguments. Applications passing untrusted collection names into these backends can trigger SQL or CQL injection, which occurs when malicious SQL or CQL statements are inserted into entry fields for execution.
Recommendations Update to version 4.6.34.

Exploit

Fix

RCE

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-44337
GHSA-3643-7V76-5CJ2

Affected Products

Praisonai