Supply Chain Vulnerability in PraisonAI by Mervin Praison
CVE-2026-40154

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
9 April 2026

What is CVE-2026-40154?

Prior to version 4.5.128, PraisonAI permitted the execution of remotely fetched template files as trusted executable code, lacking integrity verification and origin validation. This oversight allowed attackers to exploit the system through malicious templates, potentially leading to significant security breaches. The vulnerability has been addressed in the latest release, emphasizing the need for users to update their applications to ensure protection against supply chain attacks.

Affected Version(s)

PraisonAI < 4.5.128

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.