CVE-2026-40157
Critical Severity
Description
PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives using raw tar.extract() without valida...
Related Vulnerabilities
- CVE-2026-35666: OpenClaw before 2026.3.22 contains an allowlist bypass vulnerability in system.run approvals that fa HIGH
- CVE-2026-4664: The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authentication bypass in MEDIUM
- CVE-2026-3498: The BlockArt Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'clien MEDIUM
- CVE-2026-40184: TREK is a collaborative travel planner. Prior to 2.7.2, TREK served uploaded photos without requirin LOW
- CVE-2026-4151: GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow HIGH
Related Coverage
Threat Actors