Executive brief
PraisonAI, a framework for managing AI agents and knowledge bases, is vulnerable to a database injection flaw. An attacker who can influence how data collections are created can execute unauthorized commands on the underlying PostgreSQL or Cassandra database. This could lead to the complete deletion of data, unauthorized access to sensitive information, or a total service outage.
Technical details
A SQL/CQL injection vulnerability exists in PraisonAI's PGVector and Cassandra knowledge-store backends due to improper neutralization of the 'dimension' argument in the create_collection() method. While the software validates identifiers like schema and table names, the dimension value—though type-hinted as an integer—is not enforced at runtime and is directly interpolated into CREATE TABLE DDL statements. An attacker capable of influencing collection parameters can inject malicious SQL or CQL tokens (e.g., '3); DROP TABLE tenant_secrets; --') to manipulate the database schema or access data. The vulnerability is fixed in version 4.6.78 by ensuring proper validation of the dimension value before DDL execution.
Affected products
- MervinPraison PraisonAI < 4.6.78
Timeline
- 2026-06-25: advisory: GitHub Security Advisory GHSA-wf65-4jjx-q444 published
- 2026-07-11: disclosed: NVD publication date