CVE-2026-34935: Praison Praisonai
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the --mcp CLI argument is passed directly to shlex.split() and forwarded through the call chain to anyio.open_process() with no validation, allowlist check, or sanitization at any hop, allowing arbitrary OS command execution as the process user. This issue has been patched in version 4.5.69.
Affected products
- Praison Praisonai: from 4.5.15, before 4.5.69 (fixed in 4.5.69)
Published 2026-04-03. Last modified 2026-07-24.