<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 07:22:41 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-337946</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337946</link>
      <description>EUVD-2026-337946</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337946</guid>
    </item>
    <item>
      <title>fkie_cve-2026-61438</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-61438</link>
      <description>&lt;p&gt;PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML workflow files with import os statements followed by os.system() calls that bypass sandbox checks and execute arbitrary OS commands with process privileges.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML workflow files with import os statements followed by os.system() calls that bypass sandbox checks and execute arbitrary OS commands with process privileges.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-61438</guid>
    </item>
    <item>
      <title>GHSA-qh3g-555w-f82q</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qh3g-555w-f82q</link>
      <description>&lt;p&gt;PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML workflow files with import os statements followed by os.system() calls that bypass sandbox checks and execute arbitrary OS commands with process privileges.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validation of workflow script steps. Attackers can create malicious YAML workflow files with import os statements followed by os.system() calls that bypass sandbox checks and execute arbitrary OS commands with process privileges.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qh3g-555w-f82q</guid>
    </item>
  </channel>
</rss>
