logo

PraisonAI Vulnerability Exploited Within Hours of Public Disclosure

ID: 93677648-3a50-5ec1-8eb4-f9a4211f8021

STIX ID: report--93677648-3a50-5ec1-8eb4-f9a4211f8021

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-15

Date Updated: 2026-05-22

Author: Abinaya

...
...

A critical flaw (CVE-2026-44338) in PraisonAI's legacy Flask API server ships with AUTH_ENABLED = False and binds to 0.0.0.0:8080, allowing unauthenticated attackers to enumerate agents via GET /agents and trigger workflows via POST /chat to exfiltrate outputs and exhaust external AI model quotas; maintainers released version 4.6.34 and advise switching to the secure serve agents deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.