CVE-2026-34937·Python vulnerability
PraisonAI is a multi-agent teams system. Prior to version 1.5.90, run_python() in praisonai constructs a shell command string by interpolating user-controlled code into python3 -c "<code>" and passing it to subprocess.run(..., shell=True). The escaping logic only handles \ and ", leaving $() and backtick substitutions unescaped, allowing arbitrary OS command execution before Python is invoked. This issue has been patched in version 1.5.90.
- Severity
- high
- Software
- Python
- Fixed in
- 1.5.90
- Published
- 2026-04-03
Affected versions
Until: 1.5.90
Fixed in: 1.5.90
How to fix this CVE
Update PraisonAI to version 1.5.90 or later to remediate this command injection vulnerability. The patched version implements proper shell metacharacter escaping in the run_python() function, preventing attackers from injecting arbitrary OS commands through code interpolation. Verify the update has been applied and test your multi-agent workflows to ensure functionality.
sudo dnf upgrade python3-praisonaiDefensia detects this vulnerability
How to check if you are affected
- Check installed PraisonAI version: python3 -c "import praisonai; print(praisonai.__version__)"
- Verify if run_python() is exposed in your application: grep -r "run_python" /path/to/your/praisonai/code
- Search application logs for suspicious shell metacharacters in code execution: grep -E '\$\(|`|\||;|&' /var/log/application.log
- Confirm the patch: python3 -c "import praisonai; print('Patched' if praisonai.__version__ >= '1.5.90' else 'Vulnerable')"
FAQ
What is CVE-2026-34937?
This vulnerability exists in PraisonAI's run_python() function, which constructs shell commands by directly interpolating user-supplied code without properly escaping shell metacharacters like $() and backticks. An authenticated attacker can inject arbitrary OS commands that execute before Python, leading to complete system compromise.
Is CVE-2026-34937 being actively exploited?
No, this vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits are available, though the attack vector is straightforward for anyone with local or authenticated access.
What versions of PraisonAI are affected by CVE-2026-34937?
All versions of PraisonAI prior to 1.5.90 are vulnerable. Version 1.5.90 and later include the security patch.
How do I check if my server is vulnerable to CVE-2026-34937?
Run: python3 -c "import praisonai; print(praisonai.__version__)" and verify the version is 1.5.90 or later. If the version is lower, your system is vulnerable.
Does Defensia detect CVE-2026-34937?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If PraisonAI is installed on a monitored server, CVE-2026-34937 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-34937. Free for 1 server.
Get started free