CVE-2026-40158
High Severity
Description
PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can be bypassed using type.__getattribute__ trampoline, allowing ...
Related Vulnerabilities
- CVE-2026-35601: Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output MEDIUM
- CVE-2026-35595: Vikunja vulnerable to Privilege Escalation via Project Reparenting HIGH
- CVE-2025-66447: Chamilo LMS is a learning management system. From 1.11.0 to 2.0-beta.1, anyone can trigger a malicio LOW
- CVE-2026-5392: Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an OOB read on the hea LOW
- CVE-2026-36235: A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Stude CRITICAL
Related Coverage
Threat Actors