CVE-2026-40158
High Severity
Description
PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can be bypassed using type.__getattribute__ trampoline, allowing ...
Related Vulnerabilities
- CVE-2026-40175: Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain CRITICAL
- CVE-2026-35643: OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing HIGH
- CVE-2025-62718: Axios has a NO_PROXY Hostname Normalization Bypass Leads to SSRF MEDIUM
- CVE-2026-5507: When restoring a session from cache, a pointer from the serialized session data is used in a free op MEDIUM
- CVE-2026-40150: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praison HIGH
Related Coverage
Threat Actors