
CVE-2026-40114 PraisonAI is a multi-agent teams system. Prior to 4.5.128, the /api/v1/runs endpoint accepts an arbitrary webhook_url in the request body with no URL validation. When… https://www.cve.org/CVERecord?id=CVE-2026-40114
Post summary
CVE-2026-40114 highlights a flaw in PraisonAI's API that accepts arbitrary webhook URLs without validation. The post provides a basic vulnerability description but lacks a PoC, exploit code, patch, or evidence of active exploitation.


