CCB Alert@CCBalertDisclosure
The message announces two critical PraisonAI CVEs (CVE‑2026‑40088 and CVE‑2026‑40154) with a CVSS score of 9.6 that allow remote code execution, and it urges patching via a GitHub security page; no PoC or exploitation evidence is provided.
PulsePatch.io@pulsepatchioDisclosure
The post announces a critical remote code execution vulnerability in PraisonAI caused by untrusted template code, urging users to review deployments and input handling.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The advisory reports a supply‑chain vulnerability (CVE‑2026‑40154) that enables unverified remote template execution in PraisionAI versions prior to 4.5.128.
CVEFind.com@CveFindComPatch
The post announces a patch for CVE‑2026‑40154, describing the vulnerability and its mitigation, with no evidence of exploitation or PoC details.
CVE@CVEnewDisclosure
The post announces CVE‑2026‑40154, noting that PraisonAI versions prior to 4.5.128 blindly execute remotely fetched template files, allowing potential code execution.
0day Signal@0dayPublishingDisclosure
The tweet announces the discovery of CVE-2026-40154, highlighting a zero-click remote code execution vulnerability in PraisonAI that allows attackers to hijack AI workflows through malicious template poisoning.