<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 08:36:34 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-40148 — PraisonAI Affected by Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-40148</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; MervinPraison PraisonAI&lt;/p&gt;
&lt;p&gt;PraisonAI is a multi-agent teams system. Prior to 4.5.128, the _safe_extractall() function in PraisonAI&amp;#39;s recipe registry validates archive members against path traversal attacks but performs no checks on individual member sizes, cumulative extracted size, or member count before calling tar.extractall(). An attacker can publish a malicious recipe bundle containing highly compressible data (e.g., 10GB of zeros compressing to ~10MB) that exhausts the victim&amp;#39;s disk when pulled via LocalRegistry.pull() or HttpRegistry.pull(). This vulnerability is fixed in 4.5.128.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; MervinPraison PraisonAI&lt;/p&gt;
&lt;p&gt;PraisonAI is a multi-agent teams system. Prior to 4.5.128, the _safe_extractall() function in PraisonAI&amp;#39;s recipe registry validates archive members against path traversal attacks but performs no checks on individual member sizes, cumulative extracted size, or member count before calling tar.extractall(). An attacker can publish a malicious recipe bundle containing highly compressible data (e.g., 10GB of zeros compressing to ~10MB) that exhausts the victim&amp;#39;s disk when pulled via LocalRegistry.pull() or HttpRegistry.pull(). This vulnerability is fixed in 4.5.128.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-40148</guid>
    </item>
    <item>
      <title>GHSA-f2h6-7xfr-xm8w — PraisonAI Vulnerable to Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f2h6-7xfr-xm8w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PraisonAI&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `_safe_extractall()` function in PraisonAI&amp;#39;s recipe registry validates archive members against path traversal attacks but performs no checks on individual member sizes, cumulative extracted size, or member count before calling `tar.extractall()`. An attacker can publish a malicious recipe bundle containing highly compressible data (e.g., 10GB of zeros compressing to ~10MB) that exhausts the victim&amp;#39;s disk when pulled via `LocalRegistry.pull()` or `HttpRegistry.pull()`.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerable function is `_safe_extractall()` at `src/praisonai/praisonai/recipe/registry.py:131-162`:&lt;/p&gt;
&lt;p&gt;```python
def _safe_extractall(tar: tarfile.TarFile, dest_dir: Path) -&amp;gt; None:
    dest_resolved = dest_dir.resolve()
    for member in tar.getmembers():
        member_path = Path(member.name)
        # Reject absolute paths
        if member_path.is_absolute():
            raise RegistryError(...)
        # Reject &amp;#39;..&amp;#39; components
        if &amp;#39;..&amp;#39; in member_path.parts:
            raise RegistryError(...)
        # Reject resolved paths escaping dest_dir
        resolved = (dest_resolved / member_path).resolve()
        if not str(resolved).startswith(str(dest_resolved) + os.sep) and resolved != dest_resolved:
            raise RegistryError(...)
    # All members validated — safe to extract
    tar.extractall(dest_dir)  # &amp;lt;-- No size limit
```&lt;/p&gt;
&lt;p&gt;The function iterates all tar members and checks for path traversal (absolute paths, `..` components, resolved path escaping), but never…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: PraisonAI&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The `_safe_extractall()` function in PraisonAI&amp;#39;s recipe registry validates archive members against path traversal attacks but performs no checks on individual member sizes, cumulative extracted size, or member count before calling `tar.extractall()`. An attacker can publish a malicious recipe bundle containing highly compressible data (e.g., 10GB of zeros compressing to ~10MB) that exhausts the victim&amp;#39;s disk when pulled via `LocalRegistry.pull()` or `HttpRegistry.pull()`.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The vulnerable function is `_safe_extractall()` at `src/praisonai/praisonai/recipe/registry.py:131-162`:&lt;/p&gt;
&lt;p&gt;```python
def _safe_extractall(tar: tarfile.TarFile, dest_dir: Path) -&amp;gt; None:
    dest_resolved = dest_dir.resolve()
    for member in tar.getmembers():
        member_path = Path(member.name)
        # Reject absolute paths
        if member_path.is_absolute():
            raise RegistryError(...)
        # Reject &amp;#39;..&amp;#39; components
        if &amp;#39;..&amp;#39; in member_path.parts:
            raise RegistryError(...)
        # Reject resolved paths escaping dest_dir
        resolved = (dest_resolved / member_path).resolve()
        if not str(resolved).startswith(str(dest_resolved) + os.sep) and resolved != dest_resolved:
            raise RegistryError(...)
    # All members validated — safe to extract
    tar.extractall(dest_dir)  # &amp;lt;-- No size limit
```&lt;/p&gt;
&lt;p&gt;The function iterates all tar members and checks for path traversal (absolute paths, `..` components, resolved path escaping), but never…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f2h6-7xfr-xm8w</guid>
    </item>
  </channel>
</rss>
