CVE-2026-40159 - PraisonAI Exposes Sensitive Environment Variable via Untrusted MCP Subprocess Execution
CVE ID :CVE-2026-40159
Published : April 10, 2026, 5:17 p.m. | 49 minutes ago
Description :PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol)...
Related Vulnerabilities
- CVE-2026-33704: Chamilo LMS is a learning management system. Prior to 1.11.38, any authenticated user (including stu HIGH
- CVE-2026-33092: Local privilege escalation due to improper handling of environment variables. The following products HIGH
- CVE-2026-40150: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praison HIGH
- CVE-2026-40151: PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a MEDIUM
- CVE-2026-40252: FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (I N/A
Related Coverage
Threat Actors