CVE-2026-40113 | MervinPraison PraisonAI up to 4.5.127 Cloud Run Service deploy.py openai_model/openai_key/openai_base argument injection (GHSA-fvxx-ggmx-3cjg)
A vulnerability was found in MervinPraison PraisonAI up to 4.5.127. It has been classified as critical. This issue affects some unknown processing of the file deploy.py of the component Cloud Run Service. This manipulation of the argument openai_model/openai_key/openai_base causes argument injection.
This vulnerability is tracked as CVE-2026-40113. The attack is restricted to local execution. No exploit exists.
Upgrading the affected component is recommended.