PulsePatch.io@pulsepatchioDisclosure
The post announces CVE‑2026‑40289 as an unauthenticated WebSocket session hijack vulnerability in PraisonAI Browser Server and recommends restricting network access as a workaround.
CCB Alert@CCBalertPatch
The message alerts about three critical CVEs in PraisonAI and notes that patches are available.
CVEarity@CVEarityDisclosure
The tweet announces a new critical vulnerability (CVE-2026-40289) with a CVSS score of 9.1, but offers no additional technical specifics, PoC, or patch information.
0day Signal@0dayPublishingDisclosure
CVE-2026-40289 exposes a network‑exposed WebSocket in PraisonAI Browser Server with zero authentication and bypassable Origin checks, allowing instant browser session takeover. A threat alert posts a link for details, but no patch, active exploitation, or exploit code is reported.
CVE@CVEnewGeneral
The post merely references CVE‑2026‑40289 and indicates a browser bridge issue in certain PraisonAI versions, but offers no additional technical detail or actionable information.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A newly identified unauthenticated remote session hijacking vulnerability exists in PraisonAI Browser Bridge versions below 4.5.139.
CVEFind.com@CveFindComDisclosure
A security alert announces CVE‑2026‑40289, noting that un‑authenticated remote session hijacking is possible in PraisonAI <4.5.139 and praisonaiagents <1.5.140, but no PoC, exploit, active use, or patch details are provided.