Логотип exploitDog
bind:CVE-2026-40154
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-40154

Количество 2

Количество 2

nvd логотип

CVE-2026-40154

6 дней назад

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates. This vulnerability is fixed in 4.5.128.

CVSS3: 9.3
EPSS: Низкий
github логотип

GHSA-pv9q-275h-rh7x

5 дней назад

PraisonAI Vulnerable Untrusted Remote Template Code Execution

CVSS3: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-40154

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates. This vulnerability is fixed in 4.5.128.

CVSS3: 9.3
0%
Низкий
6 дней назад
github логотип
GHSA-pv9q-275h-rh7x

PraisonAI Vulnerable Untrusted Remote Template Code Execution

CVSS3: 9.3
0%
Низкий
5 дней назад

Уязвимостей на страницу