CVE-2026-40113Disclosure(praison / praisonai)

LOWCVSS 8.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PraisonAI is a multi-agent teams system. Prior to 4.5.128, deploy.py constructs a single comma-delimited string for the gcloud run deploy --set-env-vars argument by directly interpolating openai_model, openai_key, and openai_base without validating that these values do not contain commas. gcloud uses a comma as the key-value pair separator for --set-env-vars. A comma in any of the three values causes gcloud to parse the trailing text as additional KEY=VALUE definitions, injecting arbitrary environment variables into the deployed Cloud Run service. This vulnerability is fixed in 4.5.128.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonai

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
praisonai

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-10: 3Technical Details · 2026-04-10: 304-10
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40113 PraisonAI is a multi-agent teams system. Prior to 4.5.128, http://deploy.py constructs a single comma-delimited string for the gcloud run deploy --set-env-vars argument by d… https://www.cve.org/CVERecord?id=CVE-2026-40113 ----- Traducción: CVE-… http://infoflow.cloud`

    Post summary

    CVE-2026-40113 affects PraisonAI’s deploy.py, causing incorrect environment variable handling prior to version 4.5.128; no exploits, PoCs, or patches are referenced.

    0000030
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40113 PraisonAI is a multi-agent teams system. Prior to 4.5.128, http://deploy.py constructs a single comma-delimited string for the gcloud run deploy --set-env-vars argument by d… https://www.cve.org/CVERecord?id=CVE-2026-40113

    Post summary

    CVE-2026-40113 references a flaw in PraisonAI's deployment script that builds an env‑vars string, but no PoC, exploit, patch, or active exploitation is mentioned.

    00000155
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40113 Environment Variable Injection in PraisonAI Deploy Prior to Version 4.5.128 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40113

    Post summary

    The text announces CVE‑2026‑40113, an environment variable injection flaw in PraisonAI Deploy prior to version 4.5.128, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    0000051
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonai---

Explore more