CVE-2026-40112 | MervinPraison PraisonAI up to 4.5.127 Flask API Endpoint src/praisonai/api.py _sanitize_html cross site scripting (GHSA-cfg2-mxfj-j6pw)
A vulnerability categorized as problematic has been discovered in MervinPraison PraisonAI up to 4.5.127. Affected is the function _sanitize_html of the file src/praisonai/api.py of the component Flask API Endpoint. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-40112. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.