<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T21:02:11.750323+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-290474</id>
    <title>EUVD-2026-290474</title>
    <updated>2026-10-08T21:02:11.753225+00:00</updated>
    <content>EUVD-2026-290474</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-290474"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40113</id>
    <title>fkie_cve-2026-40113</title>
    <updated>2026-10-08T21:02:11.753257+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PraisonAI is a multi-agent teams system. Prior to 4.5.128, deploy.py constructs a single comma-delimited string for the gcloud run
deploy --set-env-vars argument by directly interpolating openai_model, openai_key, and openai_base without validating that these values do not contain commas. gcloud uses a comma as the key-value pair separator for --set-env-vars. A comma in any of the three values causes gcloud to parse the trailing text as additional KEY=VALUE definitions, injecting arbitrary environment variables into the deployed Cloud Run service. This vulnerability is fixed in 4.5.128.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fvxx-ggmx-3cjg</id>
    <title>GHSA-fvxx-ggmx-3cjg — PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-e…</title>
    <updated>2026-10-08T21:02:11.753290+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: PraisonAI</p>
<p>**Summary**</p>
<p>deploy.py constructs a single comma-delimited string for the gcloud run
deploy --set-env-vars argument by directly interpolating openai_model,
openai_key, and openai_base without validating that these values do not
contain commas. gcloud uses a comma as the key-value pair separator for
--set-env-vars. A comma in any of the three values causes gcloud to
parse the trailing text as additional KEY=VALUE definitions, injecting
arbitrary environment variables into the deployed Cloud Run service.</p>
<p>Grep Commands and Evidence</p>
<p>Step 1. Confirm the vulnerable string construction at line 150
```
    grep -n "set-env-vars\|openai_key\|openai_base\|openai_model" \
      src/praisonai/praisonai/deploy.py
```
    Expected output showing unsanitized interpolation:
    150:  '--set-env-vars', f'OPENAI_MODEL_NAME={openai_model},OPENAI_API_KEY={openai_key},OPENAI_API_BASE={openai_base}'</p>
<p>Step 2. Confirm no comma validation exists before this line
```
    grep -n "comma\|assertNotIn\|ValueError\|sanitize\|strip\|replace" \
      src/praisonai/praisonai/deploy.py
```
    Expected output: no results related to input validation</p>
<p>Step 3. View the full context of the vulnerable construction
```
    sed -n '140,165p' \
      src/praisonai/praisonai/deploy.py
```
    This block shows the gcloud command list where the three values are
    joined into one comma-separated string passed as a single argument
    element. gcloud receives this string and applies its own
    comma-based parsing,…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fvxx-ggmx-3cjg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2913</id>
    <title>PYSEC-2026-2913 — PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-e…</title>
    <updated>2026-10-08T21:02:11.753355+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: praisonai</p>
<p>**Summary**</p>
<p>deploy.py constructs a single comma-delimited string for the gcloud run
deploy --set-env-vars argument by directly interpolating openai_model,
openai_key, and openai_base without validating that these values do not
contain commas. gcloud uses a comma as the key-value pair separator for
--set-env-vars. A comma in any of the three values causes gcloud to
parse the trailing text as additional KEY=VALUE definitions, injecting
arbitrary environment variables into the deployed Cloud Run service.</p>
<p>Grep Commands and Evidence</p>
<p>Step 1. Confirm the vulnerable string construction at line 150
```
    grep -n "set-env-vars\|openai_key\|openai_base\|openai_model" \
      src/praisonai/praisonai/deploy.py
```
    Expected output showing unsanitized interpolation:
    150:  '--set-env-vars', f'OPENAI_MODEL_NAME={openai_model},OPENAI_API_KEY={openai_key},OPENAI_API_BASE={openai_base}'</p>
<p>Step 2. Confirm no comma validation exists before this line
```
    grep -n "comma\|assertNotIn\|ValueError\|sanitize\|strip\|replace" \
      src/praisonai/praisonai/deploy.py
```
    Expected output: no results related to input validation</p>
<p>Step 3. View the full context of the vulnerable construction
```
    sed -n '140,165p' \
      src/praisonai/praisonai/deploy.py
```
    This block shows the gcloud command list where the three values are
    joined into one comma-separated string passed as a single argument
    element. gcloud receives this string and applies its own
    comma-based parsing,…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2913"/>
  </entry>
</feed>
