
CVE-2026-39306 PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry pull flow extracts attacker-controlled .praison tar archives with tar.extractal… https://www.cve.org/CVERecord?id=CVE-2026-39306
Post summary
The post discloses that PraisonAI up to version 1.5.113 can extract attacker‑controlled .praison tar archives during recipe registry pulls, indicating a significant vulnerability.
