CVE-2026-60090

PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() backends. Although schema, keyspace, and collection-name identifiers are validated, the dimension value (declared as int but not enforced at runtime) is interpolated directly into the vector column of the generated CREATE TABLE DDL. A caller able to influence collection-creation dimensions can pass a string such as '3); DROP TABLE tenant_secrets; --' to inject SQL/CQL tokens into the statement executed by the database driver.
Configurations

No configuration.

History

14 Jul 2026, 15:17

Type Values Removed Values Added
References () https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-wf65-4jjx-q444 - () https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-wf65-4jjx-q444 -

11 Jul 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-11 14:16

Updated : 2026-07-14 15:17


NVD link : CVE-2026-60090

Mitre link : CVE-2026-60090

CVE.ORG link : CVE-2026-60090


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')