Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40148

23
FAUCET Score

OVERVIEW CVE-2026-40148 is a denial-of-service vulnerability in PraisonAI versions prior to 4.5.128 that affects the recipe registry's archive extraction functionality. The _safe_extractall() function validates archive members against path traversal attacks but lacks protections against oversized files, cumulative extraction limits, or excessive member counts. This allows attackers to distribute malicious recipe bundles containing highly compressible payloads that expand to consume available disk space when extracted by users. SEVERITY The vulnerability carries a CVSS 3.1 score of 6.5 (MEDIUM) with a network-based attack vector requiring minimal complexity and no privileges, though it does require user interaction to pull a malicious recipe. The attack has no impact on confidentiality or integrity, but causes high availability impact through disk exhaustion. The EPSS score of 0.00037 indicates this vulnerability poses lower relative risk compared to other published CVEs. EXPLOITATION STATUS Currently, there is no evidence of active exploitation, and the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog. The FAUCET Risk Score of 35.0/100 suggests limited community attention or public exploit code availability. Organizations should prioritize updating PraisonAI to version 4.5.128 or later, though the absence of active exploitation provides a reasonable window for patching before immediate risk materializes.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.5.128CPE matchmatch criteria
cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 16th percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

pippatch availablevia ghsa
Product: PraisonAIFixed in: 4.5.128

Vendor Advisories (1)

pipGHSA-f2h6-7xfr-xm8wmedium

PraisonAI Vulnerable to Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits

Apr 10, 2026

References

github.com / MervinPraison/PraisonAI/security/advisories/GHSA-f2h6-7xfr-xm8w
ExploitVendor Advisory