CVE-2026-40156 - PraisonAI Affected by Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading
CVE ID :CVE-2026-40156
Published : April 10, 2026, 5:17 p.m. | 49 minutes ago
Description :PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file nam...
Related Vulnerabilities
- CVE-2026-39414: MinIO affected a DoS via Unbounded Memory Allocation in S3 Select CSV Parsing HIGH
- CVE-2026-31939: Chamilo LMS is a learning management system. Prior to 1.11.38, there is a path traversal in main/exe HIGH
- CVE-2026-4154: GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow HIGH
- CVE-2026-33092: Local privilege escalation due to improper handling of environment variables. The following products HIGH
- CVE-2026-40158: PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI's AST-based Python sandbox can HIGH
Related Coverage
Threat Actors