CVE-2026-34952: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-34952 is a missing authentication vulnerability in the PraisonAI Gateway server that allows any unauthenticated network client to enumerate registered agents and send arbitrary messages to agents and their tool sets. It affects PraisonAI versions up to and including 4.5.96 (pip package praisonai). The vulnerability was published on March 31, 2026, and patched in version 4.5.97. It carries a CVSS v3.1 base score of 9.1 (Critical) (GitHub Advisory, PraisonAI Advisory).

Technical details

The root cause is CWE-306 (Missing Authentication for Critical Function): the websocket_endpoint handler in gateway/server.py unconditionally accepts all incoming WebSocket connections without verifying any token or credential, and the /info HTTP endpoint returns the full agent topology (agent IDs, session counts, client counts) to any requester without authentication. Notably, GatewayConfig includes an auth_token field, but it is never checked in the handler — the server calls await websocket.accept() immediately upon connection. The attack vector is purely network-based, requires no privileges or user interaction, and has low complexity since no bypass technique is needed beyond simply connecting (GitHub Advisory, PraisonAI Advisory).

Impact

An unauthenticated attacker with network access can enumerate all registered AI agents via the /info endpoint, then connect to the /ws WebSocket endpoint and send arbitrary messages to any agent, including commands that trigger tool execution, file reads, and external API calls. This results in high confidentiality impact (exposure of agent topology and data accessible to agents) and high integrity impact (unauthorized modification of agent behavior or data). There is no direct availability impact, but the ability to invoke arbitrary agent tools could facilitate lateral movement within the infrastructure or exfiltration of sensitive data processed by the agents (PraisonAI Advisory, GitHub Advisory).

Exploitability

A proof-of-concept (PoC) is publicly available in the official security advisory, consisting of runnable curl and Python commands that demonstrate agent enumeration and unauthenticated WebSocket connection on a live PraisonAI server. The PoC was confirmed to work against praisonai==4.5.87. There is no current evidence of in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.029% (9th percentile), and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, PraisonAI Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible PraisonAI Gateway instances (default port 8765) using network scanners such as Shodan, Censys, or nmap targeting the default port.
  2. Agent enumeration: Send an unauthenticated HTTP GET request to the /info endpoint to retrieve all registered agent IDs, session counts, and client counts:
    curl -s http://<target>:8765/info
    # Returns: {"name":"PraisonAI Gateway","version":"1.0.0","agents":[...],"sessions":0,"clients":0}
  3. WebSocket connection: Connect to the /ws WebSocket endpoint without providing any authentication token:
    import asyncio, websockets, json
    async def run():
        async with websockets.connect('ws://<target>:8765/ws') as ws:
            print('Connected with no auth')
            await ws.send(json.dumps({'type': 'join', 'agent_id': 'assistant'}))
            print(await asyncio.wait_for(ws.recv(), timeout=3))
    asyncio.run(run())
  4. Send arbitrary messages: Use the established WebSocket connection to send arbitrary messages to any registered agent, including commands to invoke tools (file reads, API calls, or other configured tool sets).
  5. Achieve objective: Exfiltrate data accessible to the agents, manipulate agent behavior, or use agent tool capabilities for further lateral movement within the environment (PraisonAI Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected HTTP GET requests to /info endpoint on port 8765 from external or untrusted IP addresses; WebSocket upgrade requests to /ws from unauthenticated or unknown clients.
  • Logs: Access log entries showing repeated or automated requests to GET /info and GET /ws (WebSocket upgrade) without any Authorization header or token query parameter; connections from unusual geographic locations or IP ranges.
  • Process/Behavior: Unexpected tool invocations or file read operations triggered by the PraisonAI agent process; unusual outbound API calls or network connections initiated by agent tool sets following WebSocket message receipt.
  • Application: Multiple simultaneous WebSocket client connections (clients count in /info response elevated unexpectedly); agent IDs being targeted in join messages that do not correspond to legitimate internal clients (PraisonAI Advisory).

Mitigation and workarounds

Upgrade PraisonAI to version 4.5.97 or later, which patches this vulnerability. As an interim workaround, restrict network access to the PraisonAI Gateway server (default port 8765) using firewall rules or network-level access controls to allow only trusted clients. The advisory also suggests implementing token-based authentication in the WebSocket handler by checking the token query parameter or Authorization header against GatewayConfig.auth_token before accepting the connection (GitHub Advisory, PraisonAI Advisory).

Community reactions

The vulnerability received coverage from several security community outlets and social media platforms shortly after disclosure. A blog post titled "7 CVEs in 48 Hours: How PraisonAI Got Completely Owned" was published on dev.to, highlighting the broader security posture of the PraisonAI framework. Discussions were noted on Mastodon (infosec.exchange and mastodon.social) and Bluesky, with community members flagging the ease of exploitation given the public PoC. Red Hat also tracked the vulnerability in their security advisory database (Red Hat CVE).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management