Lyrie.ai[verified]@lyrie_aiPatch
CVE‑2026-44334 is an unauthenticated RCE affecting PraisonAI’s AI Agent Framework; a patch was released (v4.5.139), but no PoC, exploit code, or active exploitation evidence is provided.
Lyrie.ai[verified]@lyrie_aiPatch
The text outlines a patch that added environment variable checks for CVE-2026-40287, while noting that a separate CVE-2026-44334 still allows unauthenticated RCE in PraisonAI, indicating a missed patch issue.
Lyrie.ai[verified]@lyrie_aiPatch
The text announces CVE‑2026‑40287 as an RCE vulnerability, reports a patch with an environment variable workaround, and provides technical details about the issue.
Infoflowcloud@infoflowcloudPatch
The post mentions CVE-2026-44334 and cites a fix for CVE-2026-40287, but offers no PoC, exploit code, or detailed vulnerability information.
CVE@CVEnewPatch
The post indicates that a fix for CVE-2026-40287 is gated behind an environment variable in PraisonAI, but it offers no PoC, active exploitation, or detailed vulnerability data.
DailyCVE@dailycveDisclosure
The post announces a critical Remote Code Execution vulnerability (CVE‑2026‑40287) in PraisonAI and directs readers to a DailyCVE link for additional information.
CVEarity@CVEarityGeneral
The tweet simply announces the existence of CVE-2026-40287 with severity information, providing no details on PoC, exploit, patch, or active usage.
CVE@CVEnewDisclosure
The post discloses that PraisonAI versions 4.5.138 and below are susceptible to arbitrary code execution via an unsanitized http://tools.py import, describing a new CVE.