VYPR
High severity7.3NVD Advisory· Published May 8, 2026· Updated May 8, 2026

CVE-2026-44338

CVE-2026-44338

Description

PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API server with authentication disabled by default. When that server is used, any caller that can reach it can access /agents and trigger the configured agents.yaml workflow through /chat without providing a token. This issue has been patched in version 4.6.34.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
PraisonAIPyPI
>= 2.5.6, < 4.6.344.6.34

Affected products

1
  • cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:*
    Range: >=2.5.6,<4.6.34

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

10