CVE-2026-40159Disclosure(praison / praisonai)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) integration allows spawning background servers via stdio using user-supplied command strings (e.g., MCP("npx -y @smithery/cli ...")). These commands are executed through Python’s subprocess module. By default, the implementation forwards the entire parent process environment to the spawned subprocess. As a result, any MCP command executed in this manner inherits all environment variables from the host process, including sensitive data such as API keys, authentication tokens, and database credentials. This behavior introduces a security risk when untrusted or third-party commands are used. In common scenarios where MCP tools are invoked via package runners such as npx -y, arbitrary code from external or potentially compromised packages may execute with access to these inherited environment variables. This creates a risk of unintended credential exposure and enables potential supply chain attacks through silent exfiltration of secrets. This vulnerability is fixed in 4.5.128.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-214

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonai

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-10); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
praisonai

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-10: 1Mentions · 2026-04-14: 1Technical Details · 2026-04-10: 104-1004-14
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-101
Disclosure1
2026-04-141
General1
Full discourse2 posts
  • SUNGLASSES@sunglasses_dev
    General

    The MCP Attack Atlas is live. 40+ AI agent attack patterns across 14 families. 1 live CVE confirmed (CVE-2026-40159). Every pattern cites a fixture or source. No benchmark theater. Open research, MIT licensed. http://sunglasses.dev/mcp-attack-atlas #AIsecurity #MCP #PromptInjection #OpenSource https://t.co/SSuuiY9m9s

    Post summary

    The tweet announces the MCP Attack Atlas as live and confirms a single CVE (CVE-2026-40159) but provides no further technical details, exploit code, or remediation information.

    2401230816
    16 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40159 PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) integration allows spawning background servers via stdio using use… https://www.cve.org/CVERecord?id=CVE-2026-40159

    Post summary

    A brief disclosure of CVE-2026-40159 affecting PraisonAI's Model Context Protocol before version 4.5.128, noting that it permits spawning background servers via stdio, with no details on exploitation or mitigation.

    00010110
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonai---

Explore more