
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34934 is a second-order SQL injection vulnerability in PraisonAI's get_all_user_threads function, located in src/praisonai/praisonai/ui/sql_alchemy.py. The function constructs raw SQL queries using Python f-strings with unescaped thread IDs retrieved from the database, allowing an attacker to store a malicious thread ID via update_thread that is later executed when the thread list is loaded. All versions of PraisonAI up to and including 4.5.89 (pip package) are affected; version 4.5.90 contains the fix. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, PraisonAI Advisory). The vulnerability was published by the maintainer on March 31, 2026, added to the GitHub Advisory Database on April 1, 2026, and published by NVD on April 3, 2026 (GitHub Advisory).
The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), specifically a second-order SQL injection pattern. At line 539 of sql_alchemy.py, an attacker-controlled string is stored as a thread ID via update_thread(thread_id=payload, user_id=user). At line 547, thread IDs are retrieved from the database and concatenated into a raw SQL string: thread_ids = "('" + "','".join([t["thread_id"] for t in user_threads]) + "'"). This unsanitized string is then interpolated directly into a SQL WHERE clause at line 576: WHERE s."threadId" IN {thread_ids}. Because the injection is stored first and triggered later (second-order), it bypasses input validation that only checks data at the point of entry. A complete Python PoC demonstrating a UNION-based injection against sqlite_master is publicly available in the advisory (PraisonAI Advisory).
Successful exploitation grants an unauthenticated remote attacker full database access, enabling exfiltration of sensitive data including user emails, session tokens, API keys, and all conversation histories. The attacker can also modify or delete any database contents, compromising data integrity and availability. Because PraisonAI is an AI agent framework that may store credentials and API keys for downstream services, a database compromise could facilitate lateral movement into connected systems (GitHub Advisory, PraisonAI Advisory).
A complete, runnable Python PoC is publicly available in the GitHub Security Advisory, demonstrating the second-order injection using actual PraisonAI library functions (SQLAlchemyDataLayer, update_thread, get_all_user_threads) (PraisonAI Advisory). No authentication or special privileges are required to exploit this vulnerability over the network. The EPSS score is approximately 0.034% (0.000480 raw), indicating a currently low but non-negligible probability of exploitation in the wild (GitHub Advisory). There is no evidence of active in-the-wild exploitation or CISA KEV catalog listing at this time, and no specific threat actor attribution has been reported (Feedly). The vulnerability was reported by researcher YeranG30 (PraisonAI Advisory).
update_thread API endpoint (or equivalent UI action) with a crafted thread ID containing a SQL injection payload, e.g.:payload = "x') UNION SELECT name, null, null, 'valid_thread', null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null FROM sqlite_master--"get_all_user_threads. The application retrieves the stored thread IDs and interpolates them unsanitized into the SQL query at line 576.sqlite_master table names) or arbitrary table contents in the thread list response.'), UNION SELECT, --, or references to internal tables like sqlite_master or information_schema.WHERE ... IN (...) clauses; errors related to SQL syntax in sql_alchemy.py at line 576; unexpected query results returning schema metadata.update_thread API endpoint with abnormally long or specially crafted thread_id parameters; subsequent requests to thread-listing endpoints from the same source IP.app.db) with anomalous thread ID entries containing SQL syntax fragments.Upgrade PraisonAI to version 4.5.90 or later, which contains the patch for this vulnerability (GitHub Advisory). As a workaround prior to patching, implement parameterized queries or prepared statements in sql_alchemy.py to replace the f-string SQL construction in get_all_user_threads. Additionally, apply strict input validation to restrict thread IDs to expected formats (e.g., alphanumeric with hyphens only) before any database operation. Review and audit other functions in sql_alchemy.py for similar raw SQL construction patterns (PraisonAI Advisory).
The vulnerability received coverage from The Hacker Wire, which published a dedicated article on the SQL injection flaw (The Hacker Wire). A dev.to post titled "7 CVEs in 48 Hours: How PraisonAI Got Completely Owned" highlighted this and related vulnerabilities as a case study in AI agent framework security, drawing community attention to the broader security posture of PraisonAI (dev.to). Social media discussion was noted on Mastodon and Bluesky, and the vulnerability was indexed by multiple threat intelligence aggregators including VulDB and CIRCL (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."