Critical

PraisonAI parse_mcp_command() CLI Argument Command Injection (CVE-2026-34935)

PraisonAI, an AI agent framework, has a command injection flaw in how it starts MCP servers. If an attacker can control the --mcp command-line value, they can make PraisonAI execute arbitrary shell commands on the host.

How the attack works

PraisonAI's CLI takes an --mcp argument meant to specify how to launch an MCP server process. That value is split with shlex.split() and handed to anyio.open_process() with no validation of what's inside it. An attacker supplies a value like `bash -c 'cat /etc/passwd'` or `python -c 'import os; os.system("id")'`, or embeds shell metacharacters such as pipes, ampersands, backticks, or $() substitutions. Because the interpreter and its inline-exec flag are passed straight through, the attacker's payload runs as a real subprocess on the machine hosting PraisonAI.

Netzilo detection

Netzilo reports this behaviour when it is observed.

Signature ID
a6b03e62-4f2b-437d-8894-080088d185aa
Severity
Critical

Why it matters

An attacker who can influence the --mcp value gets arbitrary code execution on the server running PraisonAI, which can lead to full compromise of that host and anything it has access to.

What you can do

  • Upgrade PraisonAI past version 4.5.68 or apply the vendor's fix for CVE-2026-34935.
  • Never accept --mcp values from untrusted input; treat any user- or API-supplied MCP launch command as attacker-controlled.
  • Restrict who or what can invoke the praisonai CLI with custom --mcp arguments, and run it with the least privilege necessary.
  • Monitor CLI invocations for --mcp values containing -c, -e, --exec, or shell metacharacters (|, &, `, $()) and alert on them.

Known benign look-alikes

  • Legitimate praisonai --mcp usage with npx/uvx/python -m module paths — pattern requires -c/-e inline-exec flags.
  • Security advisory text quoting CVE-2026-34935 PoC payloads for documentation.
  • Automated MCP server startup scripts using safe invocation patterns (no -c or shell metacharacters).

References

Related threats