CVE-2026-40159 - PraisonAI Exposes Sensitive Environment Variable via Untrusted MCP Subprocess Execution
CVE ID :CVE-2026-40159
Published : April 10, 2026, 5:17 p.m. | 49 minutes ago
Description :PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol)...
Related Vulnerabilities
- CVE-2026-4482: The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted MEDIUM
- CVE-2026-4156: ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability. HIGH
- CVE-2026-40150: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praison HIGH
- CVE-2026-5496: Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vulnerability HIGH
- CVE-2026-4150: GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow HIGH
Related Coverage
Threat Actors