CVE-2026-40158 - PraisonAI has Improper Control of Generation of Code ('Code Injection') and Protection Mechanism Failure in praisonai
CVE ID :CVE-2026-40158
Published : April 10, 2026, 5:17 p.m. | 49 minutes ago
Description :PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can...
Related Vulnerabilities
- CVE-2026-33092: Local privilege escalation due to improper handling of environment variables. The following products HIGH
- CVE-2026-31940: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.p HIGH
- CVE-2026-29002: CouchCMS contains a privilege escalation vulnerability that allows authenticated Admin-level users t HIGH
- CVE-2026-32146: Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows a MEDIUM
- CVE-2026-33737: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use sim MEDIUM
Related Coverage
Threat Actors