CVE-2026-40313Disclosure(praison / praisonai)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch praison praisonai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to ArtiPACKED attack, a known credential leakage vector caused by using actions/checkout without setting persist-credentials: false. By default, actions/checkout writes the GITHUB_TOKEN (and sometimes ACTIONS_RUNTIME_TOKEN) into the .git/config file for persistence, and if any subsequent workflow step uploads artifacts (build outputs, logs, test results, etc.), these tokens can be inadvertently included. Since PraisonAI is a public repository, any user with read access can download these artifacts and extract the leaked tokens, potentially enabling an attacker to push malicious code, poison releases and PyPI/Docker packages, steal repository secrets, and execute a full supply chain compromise affecting all downstream users. The issue spans numerous workflow and action files across .github/workflows/ and .github/actions/. This issue has been fixed in version 4.5.140.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-829

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonai

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-04-14); latest day: 1
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
praisonai

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-04-14: 5Mentions · 2026-04-15: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-14: 304-1404-15
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-145
Disclosure3General1Patch1
2026-04-151
Disclosure1
Full discourse6 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40313 PraisonAI is a multi-agent teams system. In versions 4.5.139 and below, the GitHub Actions workflows are vulnerable to ArtiPACKED attack, a known credential leakage v… https://www.cve.org/CVERecord?id=CVE-2026-40313

    Post summary

    The CVE-2026-40313 disclosure reports credential leakage in PraisonAI’s GitHub Actions workflows for versions 4.5.139 and below.

    1002063
    57.7K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-40313: CRITICAL] PraisonAI system had a vulnerability in versions 4.5.139 and below, with GitHub Actions workflows being exposed to ArtiPACKED attack due to credential leakage. The issue is resolve...#cve,CVE-2026-40313,#cybersecurity https://cvefind.com/CVE-2026-40313

    Post summary

    The text announces a critical CVE affecting PraisonAI, noting credential leakage in GitHub Actions workflows, but does not provide PoC, exploit code, active exploitation evidence, or patch information.

    1001075
    620 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple critical vulnerabilities in #PraisonAI CVE-2026-40313, CVE-2026-40288, CVE-2026-40289. These vulnerabilities could enable system compromise, data exposure, or full takeover. Updates are available. #Patch #Patch #Patch

    Post summary

    The message alerts users to critical PraisonAI CVEs and emphasizes that updates/patches are available to prevent possible system compromise.

    00001190
    7.2K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-40313 📊 Severity: 9.1 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-40313 #CVE-2026-40313 #CVE #Critical #CyberSecurity #InfoSec https://t.co/NtRYKyRZYI

    Post summary

    The post simply announces CVE-2026-40313, indicating its 9.1 severity with no additional technical, exploit, or mitigation details.

    0000024
    137 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40313: PraisonAI: ArtiPACKED Vulnerabil... ArtiPACKED strikes again—leaked GITHUB_TOKENs in public artifacts = instant supply chain takeover for any script kiddie... https://zerodaysignal.com/vulnerability/CVE-2026-40313 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑40313, highlighting leaked GitHub tokens that enable supply chain takeover, but provides no patches, PoC, or evidence of active exploitation.

    0000047
    218 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40313 Credential Leakage via ArtiPACKED Attack in PraisonAI Versions 4.5.139 a... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40313 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A brief alert lists CVE‑2026‑40313 as a credential leakage issue in PraisonAI, with only minimal reference links and no PoC, exploit, patch, or technical detail.

    0000034
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonai---

Explore more