CVE-2026-39890 | MervinPraison PraisonAI up to 4.5.114 API Endpoint deserialization (GHSA-32vr-5gcf-3pw2)
A vulnerability marked as critical has been reported in MervinPraison PraisonAI up to 4.5.114. Affected is an unknown function of the component API Endpoint. The manipulation leads to deserialization.
This vulnerability is referenced as CVE-2026-39890. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.