CVE-2026-40160
High Severity
Description
PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, web_crawl's httpx fallback path passes user-supplied URLs directly to httpx.AsyncClient.get() wi...
Related Vulnerabilities
- CVE-2026-35643: OpenClaw before 2026.3.22 contains an unvalidated WebView JavascriptInterface vulnerability allowing HIGH
- CVE-2026-40150: PraisonAIAgents is a multi-agent teams system. Prior to 1.5.128, the web_crawl() function in praison HIGH
- CVE-2026-5987: A security vulnerability has been detected in Sanluan PublicCMS up to 6.202506.d. This affects the f MEDIUM
- CVE-2026-5504: A padding oracle exists in wolfSSL's PKCS7 CBC decryption that could allow an attacker to recover pl MEDIUM
- CVE-2026-35666: OpenClaw before 2026.3.22 contains an allowlist bypass vulnerability in system.run approvals that fa HIGH
Related Coverage
Threat Actors