
CVE-2026-39308 PraisonAI is a multi-agent teams system. Prior to 1.5.113, PraisonAI's recipe registry publish endpoint writes uploaded recipe bundles to a filesystem path derived fr… https://www.cve.org/CVERecord?id=CVE-2026-39308
Post summary
The text announces CVE‑2026‑39308, noting that prior to version 1.5.113 PraisonAI’s recipe registry publish endpoint writes bundles to a filesystem path derived from input—highlighting a potential path traversal vulnerability. No PoC, exploit, patch, or evidence of active exploitation is provided.
