<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 11:16:33 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-290452</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290452</link>
      <description>EUVD-2026-290452</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290452</guid>
    </item>
    <item>
      <title>fkie_cve-2026-40154</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40154</link>
      <description>&lt;p&gt;PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates. This vulnerability is fixed in 4.5.128.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates. This vulnerability is fixed in 4.5.128.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-40154</guid>
    </item>
    <item>
      <title>GHSA-pv9q-275h-rh7x — PraisonAI Vulnerable Untrusted Remote Template Code Execution</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-pv9q-275h-rh7x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PraisonAI&lt;/p&gt;
&lt;p&gt;PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;When a user installs a template from a remote source (e.g., GitHub), PraisonAI downloads Python files (including `tools.py`) to a local cache without:&lt;/p&gt;
&lt;p&gt;1. Code signing verification
2. Integrity checksum validation  
3. Dangerous code pattern scanning
4. User confirmation before execution&lt;/p&gt;
&lt;p&gt;When the template is subsequently used, the cached `tools.py` is automatically loaded and executed via `exec_module()`, granting the template&amp;#39;s code full access to the user&amp;#39;s environment, filesystem, and network.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;**Template download (no verification):**
```python
# templates/registry.py:135-151
def fetch_github_template(owner, repo, template_path, ref=&amp;#34;main&amp;#34;):
    temp_dir = Path(tempfile.mkdtemp(prefix=&amp;#34;praison_template_&amp;#34;))
    
    for item in contents:
        if item[&amp;#34;type&amp;#34;] == &amp;#34;file&amp;#34;:
            file_content = self._fetch_github_file(item[&amp;#34;download_url&amp;#34;])
            file_path = temp_dir / item[&amp;#34;name&amp;#34;]
            file_path.write_bytes(file_content)  # No verification performed
```&lt;/p&gt;
&lt;p&gt;**Automatic execution (no confirmation):**
```python
# tool_resolver.py:74-80
spec = importlib.util.spec_from_file_location(&amp;#34;tools&amp;#34;, str(tools_path))
module = importlib.util.module_from_spec(spec)
spec.loader.exec_module(module)  # Executes without user con…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PraisonAI&lt;/p&gt;
&lt;p&gt;PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;When a user installs a template from a remote source (e.g., GitHub), PraisonAI downloads Python files (including `tools.py`) to a local cache without:&lt;/p&gt;
&lt;p&gt;1. Code signing verification
2. Integrity checksum validation  
3. Dangerous code pattern scanning
4. User confirmation before execution&lt;/p&gt;
&lt;p&gt;When the template is subsequently used, the cached `tools.py` is automatically loaded and executed via `exec_module()`, granting the template&amp;#39;s code full access to the user&amp;#39;s environment, filesystem, and network.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;**Template download (no verification):**
```python
# templates/registry.py:135-151
def fetch_github_template(owner, repo, template_path, ref=&amp;#34;main&amp;#34;):
    temp_dir = Path(tempfile.mkdtemp(prefix=&amp;#34;praison_template_&amp;#34;))
    
    for item in contents:
        if item[&amp;#34;type&amp;#34;] == &amp;#34;file&amp;#34;:
            file_content = self._fetch_github_file(item[&amp;#34;download_url&amp;#34;])
            file_path = temp_dir / item[&amp;#34;name&amp;#34;]
            file_path.write_bytes(file_content)  # No verification performed
```&lt;/p&gt;
&lt;p&gt;**Automatic execution (no confirmation):**
```python
# tool_resolver.py:74-80
spec = importlib.util.spec_from_file_location(&amp;#34;tools&amp;#34;, str(tools_path))
module = importlib.util.module_from_spec(spec)
spec.loader.exec_module(module)  # Executes without user con…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-pv9q-275h-rh7x</guid>
    </item>
    <item>
      <title>PYSEC-2026-476 — PraisonAI Vulnerable Untrusted Remote Template Code Execution</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-476</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonai&lt;/p&gt;
&lt;p&gt;PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;When a user installs a template from a remote source (e.g., GitHub), PraisonAI downloads Python files (including `tools.py`) to a local cache without:&lt;/p&gt;
&lt;p&gt;1. Code signing verification
2. Integrity checksum validation  
3. Dangerous code pattern scanning
 4. User confirmation before execution&lt;/p&gt;
&lt;p&gt;When the template is subsequently used, the cached `tools.py` is automatically loaded and executed via `exec_module()`, granting the template&amp;#39;s code full access to the user&amp;#39;s environment, filesystem, and network.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;**Template download (no verification):**
 ```python
# templates/registry.py:135-151
def fetch_github_template(owner, repo, template_path, ref=&amp;#34;main&amp;#34;):
    temp_dir = Path(tempfile.mkdtemp(prefix=&amp;#34;praison_template_&amp;#34;))
    
    for item in contents:
        if item[&amp;#34;type&amp;#34;] == &amp;#34;file&amp;#34;:
            file_content = self._fetch_github_file(item[&amp;#34;download_url&amp;#34;])
            file_path = temp_dir / item[&amp;#34;name&amp;#34;]
            file_path.write_bytes(file_content)  # No verification performed
```&lt;/p&gt;
&lt;p&gt;**Automatic execution (no confirmation):**
 ```python
# tool_resolver.py:74-80
spec = importlib.util.spec_from_file_location(&amp;#34;tools&amp;#34;, str(tools_path))
module = importlib.util.module_from_spec(spec)
spec.loader.exec_module(module)  # Executes without user…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: praisonai&lt;/p&gt;
&lt;p&gt;PraisonAI treats remotely fetched template files as trusted executable code without integrity verification, origin validation, or user confirmation, enabling supply chain attacks through malicious templates.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Description&lt;/p&gt;
&lt;p&gt;When a user installs a template from a remote source (e.g., GitHub), PraisonAI downloads Python files (including `tools.py`) to a local cache without:&lt;/p&gt;
&lt;p&gt;1. Code signing verification
2. Integrity checksum validation  
3. Dangerous code pattern scanning
 4. User confirmation before execution&lt;/p&gt;
&lt;p&gt;When the template is subsequently used, the cached `tools.py` is automatically loaded and executed via `exec_module()`, granting the template&amp;#39;s code full access to the user&amp;#39;s environment, filesystem, and network.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Affected Code&lt;/p&gt;
&lt;p&gt;**Template download (no verification):**
 ```python
# templates/registry.py:135-151
def fetch_github_template(owner, repo, template_path, ref=&amp;#34;main&amp;#34;):
    temp_dir = Path(tempfile.mkdtemp(prefix=&amp;#34;praison_template_&amp;#34;))
    
    for item in contents:
        if item[&amp;#34;type&amp;#34;] == &amp;#34;file&amp;#34;:
            file_content = self._fetch_github_file(item[&amp;#34;download_url&amp;#34;])
            file_path = temp_dir / item[&amp;#34;name&amp;#34;]
            file_path.write_bytes(file_content)  # No verification performed
```&lt;/p&gt;
&lt;p&gt;**Automatic execution (no confirmation):**
 ```python
# tool_resolver.py:74-80
spec = importlib.util.spec_from_file_location(&amp;#34;tools&amp;#34;, str(tools_path))
module = importlib.util.module_from_spec(spec)
spec.loader.exec_module(module)  # Executes without user…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-476</guid>
    </item>
  </channel>
</rss>
