CVE-2026-40153 | MervinPraison PraisonAIAgents up to 1.5.127 shell_tools.py os.path.expandvars exposure of sensitive information through environmental variables (GHSA-v8g7-9q6v-p3x8)
A vulnerability was found in MervinPraison PraisonAIAgents up to 1.5.127. It has been rated as problematic. This impacts the function os.path.expandvars of the file shell_tools.py. The manipulation leads to exposure of sensitive information through environmental variables.
This vulnerability is listed as CVE-2026-40153. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.