CVE-2026-40158
High Severity
Description
PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can be bypassed using type.__getattribute__ trampoline, allowing ...
Related Vulnerabilities
- CVE-2026-5507: When restoring a session from cache, a pointer from the serialized session data is used in a free op MEDIUM
- CVE-2026-40260: pypdf: Manipulated XMP metadata entity declarations can exhaust RAM MEDIUM
- CVE-2026-35620: OpenClaw before 2026.3.24 contains missing authorization vulnerabilities in the /send and /allowlist MEDIUM
- CVE-2026-32932: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Open Redirect vulne MEDIUM
- CVE-2026-5990: A vulnerability has been found in Tenda F451 1.0.0.7. Affected by this vulnerability is the function HIGH
Related Coverage
Threat Actors