AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-03T23:17:06.170Z and has not been modified since then. This critical vulnerability affects PraisonAI versions prior to 1.5.90, allowing arbitrary OS command execution on the host. The vulnerability is caused by a bypass of the three-layer sandbox in the execute_code() function, which can be achieved [truncated]
CVE-2026-34936 is a vulnerability in PraisonAI, a multi-agent teams system, that allows requests to any host reachable from the server. This issue arises from the passthrough() and apassthrough() functions in praisonai, which accept a caller-controlled api_base parameter. This parameter is concatenated with the endpoint and passed directly to httpx.Client.request() when the litellm primary path raises an [truncated]
CVE-2026-34935 is a critical vulnerability in PraisonAI, a multi-agent teams system, that allows arbitrary OS command execution. The vulnerability exists in versions 4.5.15 to before 4.5.69, where the --mcp CLI argument is passed directly to shlex.split() and forwarded to anyio.open_process() without validation, allowlist check, or sanitization. This issue enables attackers to execute OS commands as the p [truncated]
CVE-2026-34934 is a critical vulnerability in PraisonAI, a multi-agent teams system, with a CVSS score of 9.8. The vulnerability exists in the get_all_user_threads function, which constructs raw SQL queries using f-strings with unescaped thread IDs fetched from the database. An attacker can store a malicious thread ID via update_thread, and when the application loads the thread list, the injected payload [truncated]