Skip to content

PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)

High severity GitHub Reviewed Published Apr 29, 2026 in MervinPraison/PraisonAI • Updated May 12, 2026

No closed alerts for this advisory

Give feedback on Dependabot alerts