PraisonAI Vulnerability Exploited Within Hours of Public Disclosure
ID: 93677648-3a50-5ec1-8eb4-f9a4211f8021
STIX ID: report--93677648-3a50-5ec1-8eb4-f9a4211f8021
Feed Name: cybersecurityNews.com
Threat Score
A critical flaw (CVE-2026-44338) in PraisonAI's legacy Flask API server ships with AUTH_ENABLED = False and binds to 0.0.0.0:8080, allowing unauthenticated attackers to enumerate agents via GET /agents and trigger workflows via POST /chat to exfiltrate outputs and exhaust external AI model quotas; maintainers released version 4.6.34 and advise switching to the secure serve agents deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
