Junglewise Threat Intelligence

PraisonAI unauthenticated event injection in SSE server

Severity: medium · CVSS 4.3 · Published 2026-06-18

Technologies: MervinPraison/PraisonAI Praisonaiagents.

Executive brief

PraisonAI is a framework for managing AI agents. A security flaw in its server component allows unauthorized individuals to send fake messages or events to all connected users. This could be used to trick users with misleading information or disrupt the operation of AI-driven applications.

Technical details

The SSE server in `src/praisonai-agents/praisonaiagents/server/server.py` fails to implement authentication checks on critical endpoints. Specifically, the `/publish` (POST), `/events` (GET), and `/info` (GET) routes do not validate the `auth_token` defined in the `ServerConfig` dataclass. An attacker with network access to the SSE port (default 8765) can send POST requests to `/publish` to broadcast arbitrary JSON payloads to all connected SSE clients. Additionally, the `/info` endpoint leaks server configuration and the current count of connected clients. While the server binds to localhost by default, it is vulnerable when exposed via containerization or manual configuration to `0.0.0.0`. This is addressed in version 1.6.59.

Affected products

  • MervinPraison/PraisonAI praisonaiagents <= 1.6.48

Timeline

  • 2026-06-17: disclosed
  • 2026-06-18: advisory

References