Home

Description

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates. This vulnerability is fixed in 4.5.128.

PUBLISHED Reserved 2026-04-09 | Published 2026-04-09 | Updated 2026-04-10 | Assigner GitHub_M




CRITICAL: 9.3CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Problem types

CWE-829: Inclusion of Functionality from Untrusted Control Sphere

Product status

< 4.5.128
affected

References

github.com/...isonAI/security/advisories/GHSA-pv9q-275h-rh7x

cve.org (CVE-2026-40154)

nvd.nist.gov (CVE-2026-40154)

Download JSON