Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40313

32
FAUCET Score

PraisonAI versions 4.5.139 and below contain a credential leakage vulnerability in GitHub Actions workflows caused by improper use of actions/checkout without the persist-credentials: false flag. This misconfiguration allows GITHUB_TOKEN and ACTIONS_RUNTIME_TOKEN to be written into .git/config files, which can then be exposed through artifact uploads accessible to any user with read access to the public repository. The vulnerability carries a CVSS 3.1 severity rating of 9.1 (CRITICAL) with a network-based attack vector requiring no privileges or user interaction. Successful exploitation could enable attackers to push malicious code, compromise PyPI and Docker packages, exfiltrate repository secrets, and execute a full supply chain attack affecting all downstream users relying on PraisonAI and its dependencies. There is no current evidence of active exploitation in the wild, and this vulnerability does not appear on the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the public nature of the repository and ease of artifact access present a realistic exploitation pathway. The issue has been remediated in version 4.5.140, and organizations should prioritize upgrading immediately to eliminate supply chain risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.5.140CPE matchmatch criteria
cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0031 is in the 3rd percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / MervinPraison/PraisonAI/security/advisories/GHSA-3959-6v5q-45q2
Vendor Advisory
thehackernews.com / 2024/08/github-vulnerability-artipacked-exposes.html
Press/Media Coverage
unit42.paloaltonetworks.com / github-repo-artifacts-leak-tokens
MitigationThird Party Advisory