RB@RynBsdDisclosure
A tweet announces two CVEs (CVE-2026-39888 and CVE-2026-39890) as critical remote code execution vulnerabilities on the PraisonAI multi‑agent platform, with a severity score of 9.9, and provides no PoC, exploit, or patch details.
CVEFind.com@CveFindComPatch
The tweet alerts users to a critical JavaScript execution vulnerability in PrasionAI, emphasizing the need to update to version 4.5.115.
PulsePatch.io@pulsepatchioDisclosure
This tweet announces a critical RCE in PraisonAI caused by insecure YAML deserialization (CVE‑2026‑39890) and links to a PulsePatch article for more details.
Infoflowcloud@infoflowcloudDisclosure
The post announces a vulnerability in PraisonAI’s AgentService.loadAgentFromFile, noting insecure YAML parsing in versions prior to 4.5.115, but provides no PoC, exploit code, or patch details.
CVE@CVEnewDisclosure
The text discloses that PraisonAI versions before 4.5.115 are vulnerable due to insecure js‑yaml parsing in AgentService.loadAgentFromFile, without mentioning PoC, exploitation, or patch information.