Project Subscriptions
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f2h6-7xfr-xm8w | PraisonAI Vulnerable to Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 17 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Praison
Praison praisonai |
|
| CPEs | cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Praison
Praison praisonai |
Mon, 13 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mervinpraison
Mervinpraison praisonai |
|
| Vendors & Products |
Mervinpraison
Mervinpraison praisonai |
Thu, 09 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PraisonAI is a multi-agent teams system. Prior to 4.5.128, the _safe_extractall() function in PraisonAI's recipe registry validates archive members against path traversal attacks but performs no checks on individual member sizes, cumulative extracted size, or member count before calling tar.extractall(). An attacker can publish a malicious recipe bundle containing highly compressible data (e.g., 10GB of zeros compressing to ~10MB) that exhausts the victim's disk when pulled via LocalRegistry.pull() or HttpRegistry.pull(). This vulnerability is fixed in 4.5.128. | |
| Title | PraisonAI Affected by Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits | |
| Weaknesses | CWE-409 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-13T20:39:49.494Z
Reserved: 2026-04-09T19:31:56.012Z
Link: CVE-2026-40148
Updated: 2026-04-13T20:39:46.103Z
Status : Analyzed
Published: 2026-04-09T22:16:35.600
Modified: 2026-04-17T17:38:43.593
Link: CVE-2026-40148
No data.
OpenCVE Enrichment
Updated: 2026-04-10T09:28:52Z
Github GHSA