CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-34935

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-78

Description

PraisonAI is a multi-agent teams system. From version 4.5.15 to before version 4.5.69, the --mcp CLI argument is passed directly to shlex.split() and forwarded through the call chain to anyio.open_process() with no validation, allowlist check, or sanitization at any hop, allowing arbitrary OS command execution as the process user. This issue has been patched in version 4.5.69.

Affected packages

PyPI praisonai 4.5.15 → 4.5.69

References

Status: profiled · ingested 2026-07-25T00:00:18.000Z