A vulnerability described as critical has been identified in MervinPraison PraisonAI up to 4.5.112. This vulnerability affects unknown code of the component Recipe Registry Handler. The manipulation results in path traversal.

This vulnerability is known as CVE-2026-39308. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.