CVE-2026-40159
Medium Severity
Description
PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) integration allows spawning background servers via stdio us...
Related Vulnerabilities
- CVE-2026-35648: OpenClaw before 2026.3.22 contains a policy bypass vulnerability where queued node actions are not r LOW
- CVE-2026-40097: Step CA is an online certificate authority for secure, automated certificate management for DevOps. LOW
- CVE-2026-4482: The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted MEDIUM
- CVE-2026-40185: TREK is a collaborative travel planner. Prior to 2.7.2, TREK was missing authorization checks on the HIGH
- CVE-2025-5804: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio HIGH
Related Coverage
Threat Actors