Impact
PraisonAI before version 4.6.78 fails to validate the dimension argument used when creating collections in its PGVector and Cassandra back‑ends. The dimension is declared as an integer but is not enforced at runtime, so the value is directly interpolated into the CREATE influence the dimension can supply a string like "3); DROP TABLE tenant_secrets; --" and inject SQL or CQL commands into the statement executed by the database driver, enabling the execution of destructive data manipulation.
Affected Systems
The flaw affects MervinPraison’s PraisonAI application in all releases earlier running these versions is at risk regardless of its underlying operating system.
Risk and Exploitability
The CVSS score of 9.3 classifies this as a critical vulnerability. The EPSS score of <1% indicates a very low probability of exploitation at present, and the flaw is not listed in the CISA KEV catalog. The likely attack vector, inferred from the description, is acreation requests parameter, he or she can inject arbitrary SQL or CQL, potentially causing data loss or compromise of the database integrity.
OpenCVE Enrichment