SQL Injection Vulnerability in PraisonAI by MervinPraison
CVE-2026-34934
9.8CRITICAL
What is CVE-2026-34934?
The vulnerability in PraisonAI arises from the get_all_user_threads function, which creates raw SQL queries using unescaped thread IDs that are pulled from the database. Attackers can exploit this by injecting a malicious thread ID through the update_thread function. When the application retrieves the thread list, the malicious payload is executed, potentially granting the attacker full access to the database. This critical issue has been addressed in version 4.5.90, and it is highly advised for users to upgrade to ensure the security of their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PraisonAI < 4.5.90
