CVE-2026-40156
High Severity
Description
PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI automatically loads a file named tools.py from the current working directory to discover and...
Related Vulnerabilities
- CVE-2025-58913: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio HIGH
- CVE-2026-4057: The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to MEDIUM
- CVE-2026-35195: Wasmtime has out-of-bounds write or crash when transcoding component model strings MEDIUM
- CVE-2026-32894: Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, an Insecure Direct Obj HIGH
- CVE-2026-5144: The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions HIGH
Related Coverage
Threat Actors