CVE-2026-40157
Critical Severity
Description
PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives using raw tar.extract() without valida...
Related Vulnerabilities
- CVE-2026-35660: OpenClaw before 2026.3.23 contains an insufficient access control vulnerability in the Gateway agent HIGH
- CVE-2026-34946: Wasmtime has host panic when Winch compiler executes `table.fill` MEDIUM
- CVE-2026-3360: The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to an Insecu HIGH
- CVE-2026-5392: Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an OOB read on the hea LOW
- CVE-2026-4156: ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability. HIGH
Related Coverage
Threat Actors