Junglewise Threat Intelligence

CVE-2026-34952: MervinPraison PraisonAI missing authentication in WebSocket Gateway

CVE-2026-34952 · Severity: critical · CVSS 9.1 · Published 2026-04-03

Technologies: praisonai (PyPI), Praisonai. Vendors: PyPI, Praison, MervinPraison.

Executive brief

PraisonAI is a framework used to manage and coordinate teams of AI agents. A security flaw in the Gateway server allows anyone with network access to connect to the system without a password. An attacker could use this access to see all active AI agents and send them unauthorized commands, potentially leading to the theft of sensitive data or the execution of malicious actions through the agents' connected tools.

Technical details

The PraisonAI Gateway server (specifically in gateway/server.py) contains a missing authentication vulnerability (CWE-306). The `/info` endpoint leaks agent topology and IDs, while the `/ws` WebSocket endpoint accepts connections unconditionally without verifying the `auth_token` defined in `GatewayConfig`. An unauthenticated attacker can connect via the network, enumerate registered agents, and send arbitrary JSON messages to trigger agent actions, including tool execution and API calls. This issue is resolved in version 4.5.97 by implementing token validation in the WebSocket handler.

Affected products

  • MervinPraison PraisonAI < 4.5.97

Timeline

  • 2026-03-31: advisory: GitHub Security Advisory published by vendor
  • 2026-04-03: disclosed: CVE-2026-34952 published to NVD
  • 2026-04-03: patched: Fix released in version 4.5.97

References

Related threats