CVE-2026-40117 | MervinPraison PraisonAIAgents up to 1.5.127 skill_tools.py read_skill_file skill_path authorization (GHSA-grrg-5cg9-58pf)
A vulnerability was found in MervinPraison PraisonAIAgents up to 1.5.127. It has been declared as problematic. Impacted is the function read_skill_file of the file skill_tools.py. Such manipulation of the argument skill_path leads to missing authorization.
This vulnerability is listed as CVE-2026-40117. The attack must be carried out locally. There is no available exploit.
It is recommended to upgrade the affected component.