Junglewise Threat Intelligence

CVE-2026-44338: MervinPraison PraisonAI missing authentication in legacy API server

CVE-2026-44338 · Severity: high · CVSS 7.3 · Published 2026-05-11

Technologies: praisonai (PyPI). Vendors: PyPI, MervinPraison.

Executive brief

PraisonAI, a framework for managing AI agents, includes a legacy API server that has authentication disabled by default. This allows any unauthorized person with network access to the server to view agent configurations and trigger automated AI workflows. Exploitation can lead to the unauthorized consumption of expensive AI model quotas and the exposure of sensitive data processed by the agents.

Technical details

The legacy Flask API server in PraisonAI (`api_server.py`) is configured with `AUTH_ENABLED = False` and `AUTH_TOKEN = None` by default. The `check_auth()` function fails open, allowing unauthenticated access to the `/agents` and `/chat` endpoints. An attacker can reach these endpoints over the network (as the server binds to `0.0.0.0` by default) to enumerate agent metadata or trigger the execution of the `agents.yaml` workflow. This can result in unauthorized resource consumption and data exposure depending on the agent's capabilities. The issue is addressed in version 4.6.34.

Affected products

  • MervinPraison PraisonAI >= 2.5.6, <= 4.6.33

Timeline

  • 2026-05-03: disclosed: Initial disclosure by MervinPraison
  • 2026-05-08: advisory: NVD publication
  • 2026-05-11: advisory: GitHub Advisory Database publication
  • 2026-05-11: patched: Version 4.6.34 released

References

Related threats