GHSA-q65p-7p84-495cCritical· 9.8▾ MidnightDuplicate Advisory: PraisonAI: PGVector and Cassandra knowledge stores interpolate vector dimensions into DDL
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-wf65-4jjx-q444. This link is maintained to preserve external references.
PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are validated, the dimension value (declared as int but not enforced at runtime) is interpolated directly into the vector column of the generated CREATE TABLE DDL. A caller able to influence collection-creation dimensions can pass a string such as '3); DROP TABLE tenant_secrets; --' to inject SQL/CQL tokens into the statement executed by the database driver.
praisonai <= 4.6.77Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-60090Critical· 9.8PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends
GHSA-wgvq-3jxh-4qg7Medium· 5.5Duplicate Advisory: PraisonAI: Project custom command templates can read outside-workspace files into model prompts
CVE-2026-60088Medium· 5.5PraisonAI before 4.6.78 fails to validate file path references in custom command templates, allowing attackers to read files outside the workspace
GHSA-3wrm-pm5v-8vq8Medium· 7.2Duplicate Advisory: PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF
CVE-2026-60091High· 7.2PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF
GHSA-65c8-r727-2mpjHigh· 7.5Duplicate Advisory: PraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend