OVERVIEW CVE-2026-40149 is an authentication bypass vulnerability affecting PraisonAI versions prior to 4.5.128. The gateway's /api/approval/allow-list endpoint permits unauthenticated modification of the tool approval allowlist when no authentication token is configured, which is the default deployment state. By exploiting this flaw, an attacker can add dangerous tools such as shell_exec or file_write to the allowlist, causing the ExecApprovalManager to automatically approve all subsequent agent invocations of those tools and effectively bypass the human-in-the-loop safety mechanism. SEVERITY The vulnerability carries a CVSS score of 7.3 (HIGH) with a local attack vector requiring low privileges and no user interaction. The impact assessment indicates moderate confidentiality compromise combined with high integrity impact, as attackers can manipulate critical safety controls. The FAUCET Risk Score of 47.0 out of 100 reflects elevated concern despite the local attack requirement. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog, and it is not tracked on any active hot lists. The EPSS score of 0.00013 indicates extremely low predicted probability of exploitation, suggesting minimal community attention and no publicly available exploit code at this time. Organizations should prioritize patching to version 4.5.128 or later regardless of current exploitation status, given the severity of the bypass impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.128CPE matchmatch criteria | cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.