Project Subscriptions
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rg3h-x3jw-7jm5 | PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315) |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 09 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 08 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mervinpraison
Mervinpraison praisonai |
|
| Vendors & Products |
Mervinpraison
Mervinpraison praisonai |
Fri, 08 May 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Praison
Praison praisonai Praison praisonaiagents |
|
| CPEs | cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:* cpe:2.3:a:praison:praisonaiagents:*:*:*:*:*:python:*:* |
|
| Vendors & Products |
Praison
Praison praisonai Praison praisonaiagents |
Fri, 08 May 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for CVE-2026-40315 added input validation to SQLiteConversationStore only. Nine sibling backends — MySQL, PostgreSQL, async SQLite/MySQL/PostgreSQL, Turso, SingleStore, Supabase, SurrealDB — pass table_prefix straight into f-string SQL. Same root cause, same code pattern, same exploitation. 52 unvalidated injection points across the codebase. postgres.py additionally accepts an unvalidated schema parameter used directly in DDL. This issue has been patched in praisonai version 4.6.9 and praisonaiagents version 1.6.9. | |
| Title | PraisonAI: SQL Injection via unvalidated `table_prefix` in 9 conversation store backends (incomplete fix for CVE-2026-40315) | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-08T23:18:11.328Z
Reserved: 2026-04-20T16:14:19.009Z
Link: CVE-2026-41496
Updated: 2026-05-08T23:18:03.585Z
Status : Modified
Published: 2026-05-08T14:16:33.693
Modified: 2026-05-09T00:16:27.707
Link: CVE-2026-41496
No data.
OpenCVE Enrichment
Updated: 2026-05-08T21:00:09Z
Github GHSA