CVE-2026-40315Disclosure(praison / praisonai)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vulnerability in SQLiteConversationStore where the table_prefix configuration value is directly concatenated into SQL queries via f-strings without any validation or sanitization. Since SQL identifiers cannot be safely parameterized, an attacker who controls the table_prefix value (e.g., through from_yaml or from_dict configuration input) can inject arbitrary SQL fragments that alter query structure. This enables unauthorized data access, such as reading internal SQLite tables like sqlite_master, and manipulation of query results through techniques like UNION-based injection. The vulnerability propagates from configuration input in config.py, through factory.py, to the SQL query construction in sqlite.py. Exploitation requires the ability to influence configuration input, and successful exploitation leads to internal schema disclosure and full query result tampering. This issue has been fixed in version 4.5.133.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonai

Threat summary

  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Disclovery: 1 classified signal
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-04-14); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
praisonai

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-14: 2Mentions · 2026-04-15: 1Mentions · 2026-04-18: 1Mentions · 2026-05-09: 1Technical Details · 2026-04-14: 2Technical Details · 2026-04-18: 104-1404-1504-1805-09
Signal classification3 categories
Disclosure
360.0%
Disclovery
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-142
Disclosure2
2026-04-151
Disclovery1
2026-04-181
Disclosure1
2026-05-091
General1
Full discourse5 posts
  • CVE@CVEnew
    General

    CVE-2026-41496 PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for CVE-2026-40315 added input validation to SQLi… https://www.cve.org/CVERecord?id=CVE-2026-41496

    Post summary

    The text only references CVE-2026-41496 and links to its CVE record, with no further details on exploitation, patching, or vulnerability specifics.

    0001066
    57.5K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 PraisonAI, SQL Injection, #CVE-2026-40315 (High) https://dailycve.com/praisonai-sql-injection-cve-2026-40315-high/

    Post summary

    The post announces a new high‑severity SQL injection vulnerability (CVE‑2026‑40315) in PraisonAI, directing readers to a dailycve.com report for more details.

    0000038
    181 followersView on X
  • CVEarity@CVEarity
    Disclovery

    ⚡ New CVE Alert: CVE-2026-40315 📊 Severity: 7.2 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-40315 #CVE-2026-40315 #CVE #High #CyberSecurity #InfoSec https://t.co/EH2yaIhAZb

    Post summary

    The tweet announces CVE‑2026‑40315 with a severity of 7.2, indicating high risk, but provides no additional technical details or mitigation advice.

    0000030
    137 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40315 PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vulnerability in SQLiteConversationStore where the table_prefix config… https://www.cve.org/CVERecord?id=CVE-2026-40315

    Post summary

    The post announces that PraisonAI versions before 4.5.133 contain an SQL identifier injection vulnerability in SQLiteConversationStore linked to the table_prefix configuration.

    0000049
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40315 SQL Identifier Injection in PraisonAI SQLiteConversationStore Prior to 4.5.133 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40315

    Post summary

    The CVE details a SQL Identifier Injection in PraisonAI SQLiteConversationStore version prior to 4.5.133.

    0000038
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonai---

Explore more