Junglewise Threat Intelligence

CVE-2026-5594: premAI-io premsql code injection in followup worker

CVE-2026-5594 · Severity: medium · CVSS 6.3 · Published 2026-04-05

Executive brief

premAI-io premsql is a library used to integrate AI agents with SQL databases. A security flaw in the library's follow-up worker component allows an attacker to execute unauthorized code on the system. This could lead to a complete compromise of the server, unauthorized data access, or disruption of services.

Technical details

A code injection vulnerability exists in premAI-io premsql versions up to and including 0.2.1. The flaw is located in the 'eval' function within 'premsql/agents/baseline/workers/followup.py'. By manipulating the 'result' argument, a remote attacker with low privileges can inject and execute arbitrary Python code. This occurs due to improper neutralization of special elements before they are passed to a downstream component (CWE-74, CWE-94). A public exploit (PoC) is available, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • premAI-io premsql up to 0.2.1

Timeline

  • 2026-04-05: disclosed: Initial disclosure and publication of CVE-2026-5594
  • 2026-04-05: advisory

References