Daily digest
Friday 10 April 2026
51 new CVEs this day, in line with the recent average. Of those, 3 critical and 19 high. 5 arrived with exploitation evidence or public exploit code already attached. praisonai was the most-affected vendor with 13.
New this day, ranked by depth score
The 12 that matter most of the 51 published.
CVE-2026-35204High· 8.6PoCHelm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
CVE-2026-40242High· 7.2PoCArcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint
Arcane has Unauthenticated SSRF with Conditional Response Reflection in Template Fetch Endpoint
CVE-2026-34179Critical· 9.1LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin
LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin
CVE-2026-34178Critical· 9.1LXD: Importing a crafted backup leads to project restriction bypass
LXD: Importing a crafted backup leads to project restriction bypass
CVE-2026-34177Critical· 9.1LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf
LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf
CVE-2026-56075High· 8.8PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator Configuration, Enabling Unapproved Shell Command Execu…
PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator Configuration, Enabling Unapproved Shell Command Execution
CVE-2026-40158High· 8.6PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure
PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure
CVE-2026-40287High· 8.4PraisonAI Vulnerable to RCE via Automatic tools.py Import
PraisonAI Vulnerable to RCE via Automatic tools.py Import
CVE-2026-40113High· 8.4PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars
PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars
GHSA-x462-jjpc-q4q4High· 8.1PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint
CVE-2026-40156High· 7.8PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading
PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading
CVE-2026-40149High· 7.9PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls
PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls
Most-affected vendors
By CVEs published in the period.