9.3
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Description
PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates. This vulnerability is fixed in 4.5.128.
AI Analysis
Untrusted remote template code execution vulnerability in PraisonAI prior to version 4.5.128
Basic Information
ID
CVE-2026-40154
Source
GitHub_M
Published
Apr 9, 2026 at 21:42
Modified
Apr 10, 2026 at 17:09
Affected Product
Vendor
MervinPraison
Product
PraisonAI
Version
< 4.5.128
Affected Versions
MervinPraison PraisonAI < 4.5.128
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
MervinPraison
Product
PraisonAI
Version
< 4.5.128