CVE-2026-40157
Critical Severity
Description
PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives using raw tar.extract() without valida...
Related Vulnerabilities
- CVE-2026-34941: Wasmtime: Heap OOB read in component model UTF-16 to latin1+utf16 string transcoding MEDIUM
- CVE-2026-5392: Heap out-of-bounds read in PKCS7 parsing. A crafted PKCS7 message can trigger an OOB read on the hea LOW
- CVE-2026-6033: A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of MEDIUM
- CVE-2026-35602: Vikunja has File Size Limit Bypass via Vikunja Import MEDIUM
- CVE-2026-5466: wolfSSL's ECCSI signature verifier `wc_VerifyEccsiHash` decodes the `r` and `s` scalars from the sig HIGH
Related Coverage
Threat Actors