CVE-2026-34938 is a critical vulnerability affecting PraisonAI's `praisonai-agents` component prior to version 1.5.90. It allows attackers to bypass a three-layer sandbox in the `execute_code()` function, leading to arbitrary OS command execution on the host. Rated with a CVSS score of 10.0, this vulnerability is remotely exploitable with low attack complexity and no user interaction, posing a risk of complete system compromise. While no public exploits are currently available and it is not yet in CISA's KEV catalog, it is listed on a "Hot List" and has generated community discussion due to its severe impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.90CPE matchmatch criteria | cpe:2.3:a:praison:praisonaiagents:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.