CVE-2026-40151 | MervinPraison PraisonAI up to 4.5.127 /api/agents allow_origins information disclosure (GHSA-pm96-6xpr-978x)
A vulnerability labeled as problematic has been found in MervinPraison PraisonAI up to 4.5.127. Affected by this issue is the function allow_origins of the file /api/agents. Such manipulation leads to information disclosure.
This vulnerability is documented as CVE-2026-40151. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.