logo

PraisonAI Vulnerability Actively Exploited Within Hours of Being Made Public

ID: 916135c6-61e1-5d45-b67e-99914525f848

STIX ID: report--916135c6-61e1-5d45-b67e-99914525f848

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Divya

...
...

A critical authentication-bypass (CVE-2026-44338) in PraisonAI's legacy Flask-based API server (affecting versions 2.5.6–4.6.33) exposes endpoints bound to 0.0.0.0:8080 that allow unauthenticated attackers to enumerate agents and remotely execute predefined AI workflows via GET/agents and POST/chat; exploitation was observed within hours of public disclosure, and users are advised to upgrade to 4.6.34 or mitigate by restricting network access and enabling authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.