
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34952 is a missing authentication vulnerability in the PraisonAI Gateway server that allows any unauthenticated network client to enumerate registered agents and send arbitrary messages to agents and their tool sets. It affects PraisonAI versions up to and including 4.5.96 (pip package praisonai). The vulnerability was published on March 31, 2026, and patched in version 4.5.97. It carries a CVSS v3.1 base score of 9.1 (Critical) (GitHub Advisory, PraisonAI Advisory).
The root cause is CWE-306 (Missing Authentication for Critical Function): the websocket_endpoint handler in gateway/server.py unconditionally accepts all incoming WebSocket connections without verifying any token or credential, and the /info HTTP endpoint returns the full agent topology (agent IDs, session counts, client counts) to any requester without authentication. Notably, GatewayConfig includes an auth_token field, but it is never checked in the handler — the server calls await websocket.accept() immediately upon connection. The attack vector is purely network-based, requires no privileges or user interaction, and has low complexity since no bypass technique is needed beyond simply connecting (GitHub Advisory, PraisonAI Advisory).
An unauthenticated attacker with network access can enumerate all registered AI agents via the /info endpoint, then connect to the /ws WebSocket endpoint and send arbitrary messages to any agent, including commands that trigger tool execution, file reads, and external API calls. This results in high confidentiality impact (exposure of agent topology and data accessible to agents) and high integrity impact (unauthorized modification of agent behavior or data). There is no direct availability impact, but the ability to invoke arbitrary agent tools could facilitate lateral movement within the infrastructure or exfiltration of sensitive data processed by the agents (PraisonAI Advisory, GitHub Advisory).
A proof-of-concept (PoC) is publicly available in the official security advisory, consisting of runnable curl and Python commands that demonstrate agent enumeration and unauthenticated WebSocket connection on a live PraisonAI server. The PoC was confirmed to work against praisonai==4.5.87. There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.029% (9th percentile), and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, PraisonAI Advisory).
/info endpoint to retrieve all registered agent IDs, session counts, and client counts:curl -s http://<target>:8765/info
# Returns: {"name":"PraisonAI Gateway","version":"1.0.0","agents":[...],"sessions":0,"clients":0}/ws WebSocket endpoint without providing any authentication token:import asyncio, websockets, json
async def run():
async with websockets.connect('ws://<target>:8765/ws') as ws:
print('Connected with no auth')
await ws.send(json.dumps({'type': 'join', 'agent_id': 'assistant'}))
print(await asyncio.wait_for(ws.recv(), timeout=3))
asyncio.run(run())/info endpoint on port 8765 from external or untrusted IP addresses; WebSocket upgrade requests to /ws from unauthenticated or unknown clients.GET /info and GET /ws (WebSocket upgrade) without any Authorization header or token query parameter; connections from unusual geographic locations or IP ranges.clients count in /info response elevated unexpectedly); agent IDs being targeted in join messages that do not correspond to legitimate internal clients (PraisonAI Advisory).Upgrade PraisonAI to version 4.5.97 or later, which patches this vulnerability. As an interim workaround, restrict network access to the PraisonAI Gateway server (default port 8765) using firewall rules or network-level access controls to allow only trusted clients. The advisory also suggests implementing token-based authentication in the WebSocket handler by checking the token query parameter or Authorization header against GatewayConfig.auth_token before accepting the connection (GitHub Advisory, PraisonAI Advisory).
The vulnerability received coverage from several security community outlets and social media platforms shortly after disclosure. A blog post titled "7 CVEs in 48 Hours: How PraisonAI Got Completely Owned" was published on dev.to, highlighting the broader security posture of the PraisonAI framework. Discussions were noted on Mastodon (infosec.exchange and mastodon.social) and Bluesky, with community members flagging the ease of exploitation given the public PoC. Red Hat also tracked the vulnerability in their security advisory database (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."