CVE-2026-40157
Critical Severity
Description
PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives using raw tar.extract() without valida...
Related Vulnerabilities
- CVE-2026-5994: A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This issue affects the CRITICAL
- CVE-2026-23900: Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0 MEDIUM
- CVE-2026-29146: Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration.
This MEDIUM
- CVE-2026-34983: Wasmtime has use-after-free bug after cloning `wasmtime::Linker` MEDIUM
- CVE-2026-34943: Wasmtime has a possible panic when lifting `flags` component value MEDIUM
Related Coverage
Threat Actors