CyberRota Analysis
AI-GeneratedPraisonAI versions prior to 4.6.78 are vulnerable due to improper validation of the dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends, allowing attackers to inject malicious SQL/CQL commands. This critical vulnerability can lead to unauthorized data manipulation, including the potential deletion of tables. Organizations using affected versions should prioritize immediate updates to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are validated, the dimension value (declared as int but not enforced at runtime) is interpolated directly into the vector column of the generated CREATE TABLE DDL. A caller able to influence collection-creation dimensions can pass a string such as '3); DROP TABLE tenant_secrets; --' to inject SQL/CQL tokens into the statement executed by the database driver.