CVE-2026-34955 | MervinPraison PraisonAI up to 4.5.96 subprocess.run os command injection (GHSA-r4f2-3m54-pp7q)
A vulnerability was found in MervinPraison PraisonAI up to 4.5.96. It has been classified as critical. The impacted element is the function subprocess.run. The manipulation leads to os command injection.
This vulnerability is documented as CVE-2026-34955. The attack needs to be performed locally. There is not any exploit available.
Upgrading the affected component is recommended.