CVE-2026-44338: high-severity vulnerability in MervinPraison PraisonAI
PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution
Published
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
PraisonAI includes a legacy API server that runs without authentication by default, allowing anyone who can reach it to execute workflows and access agent configurations without needing credentials.
The legacy Flask API server in PraisonAI versions 2.5.6 to before 4.6.34 exposes /agents and /chat endpoints without authentication checks, enabling unauthenticated remote workflow execution (CWE-306) and information disclosure via CWE-668. Attack vector is network-based for any instance accessible without firewall restrictions.
In the same product, most dangerous first.