CVE-2026-40158
High Severity
Description
PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can be bypassed using type.__getattribute__ trampoline, allowing ...
Related Vulnerabilities
- CVE-2026-5504: A padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to recover pl MEDIUM
- CVE-2026-5507: When restoring a session from cache, a pointer from the serialized session data is used in a free op MEDIUM
- CVE-2026-35596: Vikunja has Broken Access Control on Label Read via SQL Operator Precedence Bug MEDIUM
- CVE-2026-6042: A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the MEDIUM
- CVE-2026-35600: Vikunja has HTML Injection via Task Titles in Overdue Email Notifications MEDIUM
Related Coverage
Threat Actors