<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T23:24:33.716152+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-290452</id>
    <title>EUVD-2026-290452</title>
    <updated>2026-10-08T23:24:33.718995+00:00</updated>
    <content>EUVD-2026-290452</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-290452"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40154</id>
    <title>fkie_cve-2026-40154</title>
    <updated>2026-10-08T23:24:33.719027+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates. This vulnerability is fixed in 4.5.128.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40154"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-pv9q-275h-rh7x</id>
    <title>GHSA-pv9q-275h-rh7x — PraisonAI Vulnerable Untrusted Remote Template Code Execution</title>
    <updated>2026-10-08T23:24:33.719058+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: PraisonAI</p>
<p>PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates.</p>
<p>---</p>
<p>## Description</p>
<p>When a user installs a template from a remote source (e.g., GitHub), PraisonAI downloads Python files (including `tools.py`) to a local cache without:</p>
<p>1. Code signing verification
2. Integrity checksum validation  
3. Dangerous code pattern scanning
4. User confirmation before execution</p>
<p>When the template is subsequently used, the cached `tools.py` is automatically loaded and executed via `exec_module()`, granting the template's code full access to the user's environment, filesystem, and network.</p>
<p>---</p>
<p>## Affected Code</p>
<p>**Template download (no verification):**
```python
# templates/registry.py:135-151
def fetch_github_template(owner, repo, template_path, ref="main"):
    temp_dir = Path(tempfile.mkdtemp(prefix="praison_template_"))
    
    for item in contents:
        if item["type"] == "file":
            file_content = self._fetch_github_file(item["download_url"])
            file_path = temp_dir / item["name"]
            file_path.write_bytes(file_content)  # No verification performed
```</p>
<p>**Automatic execution (no confirmation):**
```python
# tool_resolver.py:74-80
spec = importlib.util.spec_from_file_location("tools", str(tools_path))
module = importlib.util.module_from_spec(spec)
spec.loader.exec_module(module)  # Executes without user con…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-pv9q-275h-rh7x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-476</id>
    <title>PYSEC-2026-476 — PraisonAI Vulnerable Untrusted Remote Template Code Execution</title>
    <updated>2026-10-08T23:24:33.719122+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: praisonai</p>
<p>PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates.</p>
<p>---</p>
<p>## Description</p>
<p>When a user installs a template from a remote source (e.g., GitHub), PraisonAI downloads Python files (including `tools.py`) to a local cache without:</p>
<p>1. Code signing verification
2. Integrity checksum validation  
3. Dangerous code pattern scanning
 4. User confirmation before execution</p>
<p>When the template is subsequently used, the cached `tools.py` is automatically loaded and executed via `exec_module()`, granting the template's code full access to the user's environment, filesystem, and network.</p>
<p>---</p>
<p>## Affected Code</p>
<p>**Template download (no verification):**
 ```python
# templates/registry.py:135-151
def fetch_github_template(owner, repo, template_path, ref="main"):
    temp_dir = Path(tempfile.mkdtemp(prefix="praison_template_"))
    
    for item in contents:
        if item["type"] == "file":
            file_content = self._fetch_github_file(item["download_url"])
            file_path = temp_dir / item["name"]
            file_path.write_bytes(file_content)  # No verification performed
```</p>
<p>**Automatic execution (no confirmation):**
 ```python
# tool_resolver.py:74-80
spec = importlib.util.spec_from_file_location("tools", str(tools_path))
module = importlib.util.module_from_spec(spec)
spec.loader.exec_module(module)  # Executes without user…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-476"/>
  </entry>
</feed>
