CVE-2026-40157
Critical Severity
Description
PraisonAI is a multi-agent teams system. Prior to 4.5.128, cmd_unpack in the recipe CLI extracts .praison tar archives using raw tar.extract() without valida...
Related Vulnerabilities
- CVE-2026-32893: Chamilo LMS is a learning management system. Prior to 2.0.0-RC.3, a Reflected Cross-Site Scripting ( MEDIUM
- CVE-2026-4154: GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allow HIGH
- CVE-2026-35195: Wasmtime has out-of-bounds write or crash when transcoding component model strings MEDIUM
- CVE-2026-35594: Vikunja: Link Share JWT tokens remain valid for 72 hours after share deletion or permission downgrad MEDIUM
- CVE-2026-4057: The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to MEDIUM
Related Coverage
Threat Actors