PraisonAI Vulnerability Exploited Hours After Public Disclosure
ID: 31dd55ff-e378-5aab-a5bb-503f1199d9c6
STIX ID: report--31dd55ff-e378-5aab-a5bb-503f1199d9c6
Feed Name: Cyber Press
PraisonAI suffers an authentication-bypass vulnerability (CVE-2026-44338) in its legacy Flask API shipped with AUTH_ENABLED = False and bound to 0.0.0.0:8080, allowing unauthenticated attackers to GET /agents and POST /chat to remotely execute predefined AI workflows, enumerate agent configs, drain quotas, and access sensitive outputs; the issue affects versions 2.5.6 through 4.6.33, was observed being actively exploited shortly after disclosure, and is fixed in 4.6.34 with recommended mitigations including firewall restrictions, disabling public exposure, enabling auth, or migrating to the newer secure server.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
