CVE-2026-34934: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-34934 is a second-order SQL injection vulnerability in PraisonAI's get_all_user_threads function, located in src/praisonai/praisonai/ui/sql_alchemy.py. The function constructs raw SQL queries using Python f-strings with unescaped thread IDs retrieved from the database, allowing an attacker to store a malicious thread ID via update_thread that is later executed when the thread list is loaded. All versions of PraisonAI up to and including 4.5.89 (pip package) are affected; version 4.5.90 contains the fix. It carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, PraisonAI Advisory). The vulnerability was published by the maintainer on March 31, 2026, added to the GitHub Advisory Database on April 1, 2026, and published by NVD on April 3, 2026 (GitHub Advisory).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), specifically a second-order SQL injection pattern. At line 539 of sql_alchemy.py, an attacker-controlled string is stored as a thread ID via update_thread(thread_id=payload, user_id=user). At line 547, thread IDs are retrieved from the database and concatenated into a raw SQL string: thread_ids = "('" + "','".join([t["thread_id"] for t in user_threads]) + "'"). This unsanitized string is then interpolated directly into a SQL WHERE clause at line 576: WHERE s."threadId" IN {thread_ids}. Because the injection is stored first and triggered later (second-order), it bypasses input validation that only checks data at the point of entry. A complete Python PoC demonstrating a UNION-based injection against sqlite_master is publicly available in the advisory (PraisonAI Advisory).

Impact

Successful exploitation grants an unauthenticated remote attacker full database access, enabling exfiltration of sensitive data including user emails, session tokens, API keys, and all conversation histories. The attacker can also modify or delete any database contents, compromising data integrity and availability. Because PraisonAI is an AI agent framework that may store credentials and API keys for downstream services, a database compromise could facilitate lateral movement into connected systems (GitHub Advisory, PraisonAI Advisory).

Exploitability

A complete, runnable Python PoC is publicly available in the GitHub Security Advisory, demonstrating the second-order injection using actual PraisonAI library functions (SQLAlchemyDataLayer, update_thread, get_all_user_threads) (PraisonAI Advisory). No authentication or special privileges are required to exploit this vulnerability over the network. The EPSS score is approximately 0.034% (0.000480 raw), indicating a currently low but non-negligible probability of exploitation in the wild (GitHub Advisory). There is no evidence of active in-the-wild exploitation or CISA KEV catalog listing at this time, and no specific threat actor attribution has been reported (Feedly). The vulnerability was reported by researcher YeranG30 (PraisonAI Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing PraisonAI instances running versions ≤ 4.5.89, using tools like Shodan or Censys to locate exposed web UIs or API endpoints.
  2. Store malicious thread ID: Send a request to the update_thread API endpoint (or equivalent UI action) with a crafted thread ID containing a SQL injection payload, e.g.:
payload = "x') UNION SELECT name, null, null, 'valid_thread', null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null, null FROM sqlite_master--"
  1. Persist the payload: The malicious thread ID is stored in the database without sanitization, completing the "first order" of the second-order injection.
  2. Trigger the vulnerable function: Access the thread list endpoint or UI page that calls get_all_user_threads. The application retrieves the stored thread IDs and interpolates them unsanitized into the SQL query at line 576.
  3. Extract data: The injected UNION SELECT executes, returning database schema information (e.g., sqlite_master table names) or arbitrary table contents in the thread list response.
  4. Escalate: Craft additional payloads to exfiltrate user credentials, session tokens, API keys, or conversation histories, or issue UPDATE/DELETE statements to modify or destroy data (PraisonAI Advisory).

Indicators of compromise

  • Database: Thread IDs in the database containing SQL metacharacters such as single quotes ('), UNION SELECT, --, or references to internal tables like sqlite_master or information_schema.
  • Logs: Application or database query logs showing malformed or unexpectedly long SQL WHERE ... IN (...) clauses; errors related to SQL syntax in sql_alchemy.py at line 576; unexpected query results returning schema metadata.
  • Network: Unusual or repeated requests to the update_thread API endpoint with abnormally long or specially crafted thread_id parameters; subsequent requests to thread-listing endpoints from the same source IP.
  • File System: Unexpected database files (e.g., app.db) with anomalous thread ID entries containing SQL syntax fragments.
  • Process/Application: Unexpected data appearing in thread list responses, such as internal table names or columns not normally present in thread objects (PraisonAI Advisory).

Mitigation and workarounds

Upgrade PraisonAI to version 4.5.90 or later, which contains the patch for this vulnerability (GitHub Advisory). As a workaround prior to patching, implement parameterized queries or prepared statements in sql_alchemy.py to replace the f-string SQL construction in get_all_user_threads. Additionally, apply strict input validation to restrict thread IDs to expected formats (e.g., alphanumeric with hyphens only) before any database operation. Review and audit other functions in sql_alchemy.py for similar raw SQL construction patterns (PraisonAI Advisory).

Community reactions

The vulnerability received coverage from The Hacker Wire, which published a dedicated article on the SQL injection flaw (The Hacker Wire). A dev.to post titled "7 CVEs in 48 Hours: How PraisonAI Got Completely Owned" highlighted this and related vulnerabilities as a case study in AI agent framework security, drawing community attention to the broader security posture of PraisonAI (dev.to). Social media discussion was noted on Mastodon and Bluesky, and the vulnerability was indexed by multiple threat intelligence aggregators including VulDB and CIRCL (Feedly).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management