CVE-2026-34937 is a high-severity command injection vulnerability (CWE-78) affecting PraisonAI multi-agent teams systems prior to version 1.5.90. The flaw allows an authenticated local attacker with low privileges to execute arbitrary operating system commands due to insufficient escaping of user-controlled input within shell command strings. This vulnerability carries a CVSS v3.1 score of 7.8 (High), indicating significant impacts on confidentiality, integrity, and availability. Although there is no evidence of active exploitation or public exploit code, the vulnerability is on a "Hot List" and has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.90CPE matchmatch criteria | cpe:2.3:a:praison:praisonaiagents:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.