Junglewise Threat Intelligence

CVE-2026-57128: PraisonAI authentication bypass in SSE server endpoints

CVE-2026-57128 · Severity: medium · CVSS 4.3 · Published 2026-09-14

Technologies: praisonaiagents (PyPI). Vendors: PyPI, PraisonAI.

Executive brief

PraisonAI is a multi-agent AI system that uses Server-Sent Events (SSE) for real-time communication between the server and connected clients. The vulnerability allows unauthenticated network clients to broadcast arbitrary events to all connected users, disrupt communications, and retrieve sensitive server configuration and statistics without proper authorization. This could allow attackers to manipulate client interactions, obtain operational information, and potentially inject malicious content into client streams.

Technical details

The SSE server in PraisonAI versions prior to 1.6.58 fails to validate the ServerConfig.auth_token before processing requests to the /publish, /events, and /info endpoints. An attacker with network access to the server can send unauthenticated HTTP requests to these endpoints to broadcast events to all connected clients and retrieve server metadata including configuration and active client counts. No authentication, special privileges, or user interaction is required. The vulnerability was patched in version 1.6.58 by implementing proper authentication token validation on the affected endpoints.

Affected products

  • PraisonAI PraisonAI prior to 1.6.58

Timeline

  • 2026-09-14: disclosed: CVE-2026-57128 published
  • 2026-06-13: patched: Fixed in version 1.6.58

References

Related threats