<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 21:01:55 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-290474</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290474</link>
      <description>EUVD-2026-290474</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290474</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40113</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40113</link>
      <description>&lt;p&gt;PraisonAI is a multi-agent teams system. Prior to 4.5.128, deploy.py constructs a single comma-delimited string for the gcloud run
deploy --set-env-vars argument by directly interpolating openai_model, openai_key, and openai_base without validating that these values do not contain commas. gcloud uses a comma as the key-value pair separator for --set-env-vars. A comma in any of the three values causes gcloud to parse the trailing text as additional KEY=VALUE definitions, injecting arbitrary environment variables into the deployed Cloud Run service. This vulnerability is fixed in 4.5.128.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PraisonAI is a multi-agent teams system. Prior to 4.5.128, deploy.py constructs a single comma-delimited string for the gcloud run
deploy --set-env-vars argument by directly interpolating openai_model, openai_key, and openai_base without validating that these values do not contain commas. gcloud uses a comma as the key-value pair separator for --set-env-vars. A comma in any of the three values causes gcloud to parse the trailing text as additional KEY=VALUE definitions, injecting arbitrary environment variables into the deployed Cloud Run service. This vulnerability is fixed in 4.5.128.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40113</guid>
    </item>
    <item>
      <title>GHSA-fvxx-ggmx-3cjg — PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-e…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fvxx-ggmx-3cjg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PraisonAI&lt;/p&gt;
&lt;p&gt;**Summary**&lt;/p&gt;
&lt;p&gt;deploy.py constructs a single comma-delimited string for the gcloud run
deploy --set-env-vars argument by directly interpolating openai_model,
openai_key, and openai_base without validating that these values do not
contain commas. gcloud uses a comma as the key-value pair separator for
--set-env-vars. A comma in any of the three values causes gcloud to
parse the trailing text as additional KEY=VALUE definitions, injecting
arbitrary environment variables into the deployed Cloud Run service.&lt;/p&gt;
&lt;p&gt;Grep Commands and Evidence&lt;/p&gt;
&lt;p&gt;Step 1. Confirm the vulnerable string construction at line 150
```
    grep -n &amp;#34;set-env-vars\|openai_key\|openai_base\|openai_model&amp;#34; \
      src/praisonai/praisonai/deploy.py
```
    Expected output showing unsanitized interpolation:
    150:  &amp;#39;--set-env-vars&amp;#39;, f&amp;#39;OPENAI_MODEL_NAME={openai_model},OPENAI_API_KEY={openai_key},OPENAI_API_BASE={openai_base}&amp;#39;&lt;/p&gt;
&lt;p&gt;Step 2. Confirm no comma validation exists before this line
```
    grep -n &amp;#34;comma\|assertNotIn\|ValueError\|sanitize\|strip\|replace&amp;#34; \
      src/praisonai/praisonai/deploy.py
```
    Expected output: no results related to input validation&lt;/p&gt;
&lt;p&gt;Step 3. View the full context of the vulnerable construction
```
    sed -n &amp;#39;140,165p&amp;#39; \
      src/praisonai/praisonai/deploy.py
```
    This block shows the gcloud command list where the three values are
    joined into one comma-separated string passed as a single argument
    element. gcloud receives this string and applies its own
    comma-based parsing,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PraisonAI&lt;/p&gt;
&lt;p&gt;**Summary**&lt;/p&gt;
&lt;p&gt;deploy.py constructs a single comma-delimited string for the gcloud run
deploy --set-env-vars argument by directly interpolating openai_model,
openai_key, and openai_base without validating that these values do not
contain commas. gcloud uses a comma as the key-value pair separator for
--set-env-vars. A comma in any of the three values causes gcloud to
parse the trailing text as additional KEY=VALUE definitions, injecting
arbitrary environment variables into the deployed Cloud Run service.&lt;/p&gt;
&lt;p&gt;Grep Commands and Evidence&lt;/p&gt;
&lt;p&gt;Step 1. Confirm the vulnerable string construction at line 150
```
    grep -n &amp;#34;set-env-vars\|openai_key\|openai_base\|openai_model&amp;#34; \
      src/praisonai/praisonai/deploy.py
```
    Expected output showing unsanitized interpolation:
    150:  &amp;#39;--set-env-vars&amp;#39;, f&amp;#39;OPENAI_MODEL_NAME={openai_model},OPENAI_API_KEY={openai_key},OPENAI_API_BASE={openai_base}&amp;#39;&lt;/p&gt;
&lt;p&gt;Step 2. Confirm no comma validation exists before this line
```
    grep -n &amp;#34;comma\|assertNotIn\|ValueError\|sanitize\|strip\|replace&amp;#34; \
      src/praisonai/praisonai/deploy.py
```
    Expected output: no results related to input validation&lt;/p&gt;
&lt;p&gt;Step 3. View the full context of the vulnerable construction
```
    sed -n &amp;#39;140,165p&amp;#39; \
      src/praisonai/praisonai/deploy.py
```
    This block shows the gcloud command list where the three values are
    joined into one comma-separated string passed as a single argument
    element. gcloud receives this string and applies its own
    comma-based parsing,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fvxx-ggmx-3cjg</guid>
    </item>
    <item>
      <title>PYSEC-2026-2913 — PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-e…</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2913</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonai&lt;/p&gt;
&lt;p&gt;**Summary**&lt;/p&gt;
&lt;p&gt;deploy.py constructs a single comma-delimited string for the gcloud run
deploy --set-env-vars argument by directly interpolating openai_model,
openai_key, and openai_base without validating that these values do not
contain commas. gcloud uses a comma as the key-value pair separator for
--set-env-vars. A comma in any of the three values causes gcloud to
parse the trailing text as additional KEY=VALUE definitions, injecting
arbitrary environment variables into the deployed Cloud Run service.&lt;/p&gt;
&lt;p&gt;Grep Commands and Evidence&lt;/p&gt;
&lt;p&gt;Step 1. Confirm the vulnerable string construction at line 150
```
    grep -n &amp;#34;set-env-vars\|openai_key\|openai_base\|openai_model&amp;#34; \
      src/praisonai/praisonai/deploy.py
```
    Expected output showing unsanitized interpolation:
    150:  &amp;#39;--set-env-vars&amp;#39;, f&amp;#39;OPENAI_MODEL_NAME={openai_model},OPENAI_API_KEY={openai_key},OPENAI_API_BASE={openai_base}&amp;#39;&lt;/p&gt;
&lt;p&gt;Step 2. Confirm no comma validation exists before this line
```
    grep -n &amp;#34;comma\|assertNotIn\|ValueError\|sanitize\|strip\|replace&amp;#34; \
      src/praisonai/praisonai/deploy.py
```
    Expected output: no results related to input validation&lt;/p&gt;
&lt;p&gt;Step 3. View the full context of the vulnerable construction
```
    sed -n &amp;#39;140,165p&amp;#39; \
      src/praisonai/praisonai/deploy.py
```
    This block shows the gcloud command list where the three values are
    joined into one comma-separated string passed as a single argument
    element. gcloud receives this string and applies its own
    comma-based parsing,…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonai&lt;/p&gt;
&lt;p&gt;**Summary**&lt;/p&gt;
&lt;p&gt;deploy.py constructs a single comma-delimited string for the gcloud run
deploy --set-env-vars argument by directly interpolating openai_model,
openai_key, and openai_base without validating that these values do not
contain commas. gcloud uses a comma as the key-value pair separator for
--set-env-vars. A comma in any of the three values causes gcloud to
parse the trailing text as additional KEY=VALUE definitions, injecting
arbitrary environment variables into the deployed Cloud Run service.&lt;/p&gt;
&lt;p&gt;Grep Commands and Evidence&lt;/p&gt;
&lt;p&gt;Step 1. Confirm the vulnerable string construction at line 150
```
    grep -n &amp;#34;set-env-vars\|openai_key\|openai_base\|openai_model&amp;#34; \
      src/praisonai/praisonai/deploy.py
```
    Expected output showing unsanitized interpolation:
    150:  &amp;#39;--set-env-vars&amp;#39;, f&amp;#39;OPENAI_MODEL_NAME={openai_model},OPENAI_API_KEY={openai_key},OPENAI_API_BASE={openai_base}&amp;#39;&lt;/p&gt;
&lt;p&gt;Step 2. Confirm no comma validation exists before this line
```
    grep -n &amp;#34;comma\|assertNotIn\|ValueError\|sanitize\|strip\|replace&amp;#34; \
      src/praisonai/praisonai/deploy.py
```
    Expected output: no results related to input validation&lt;/p&gt;
&lt;p&gt;Step 3. View the full context of the vulnerable construction
```
    sed -n &amp;#39;140,165p&amp;#39; \
      src/praisonai/praisonai/deploy.py
```
    This block shows the gcloud command list where the three values are
    joined into one comma-separated string passed as a single argument
    element. gcloud receives this string and applies its own
    comma-based parsing,…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2913</guid>
    </item>
  </channel>
</rss>
