PraisonAI Vulnerability Actively Exploited Within Hours of Being Made Public
ID: 916135c6-61e1-5d45-b67e-99914525f848
STIX ID: report--916135c6-61e1-5d45-b67e-99914525f848
Feed Name: GBHackers
Threat Score
A critical authentication-bypass (CVE-2026-44338) in PraisonAI's legacy Flask-based API server (affecting versions 2.5.6–4.6.33) exposes endpoints bound to 0.0.0.0:8080 that allow unauthenticated attackers to enumerate agents and remotely execute predefined AI workflows via GET/agents and POST/chat; exploitation was observed within hours of public disclosure, and users are advised to upgrade to 4.6.34 or mitigate by restricting network access and enabling authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
