CVE-2026-39889: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-39889 is a missing authentication vulnerability in the A2U (Agent-to-User) event stream server component of PraisonAI, an AI agent framework. The flaw allows unauthenticated network attackers to subscribe to and receive live Server-Sent Events (SSE) streams containing all agent activity, including responses, internal reasoning, and tool call arguments. It affects PraisonAI versions up to and including 4.5.114, and is a separate issue from the related gateway server vulnerability CVE-2026-34952. The vulnerability was published on April 7–8, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, PraisonAI Advisory).

Technical details

The root cause is CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), stemming from the create_a2u_routes() function registering multiple API endpoints without any authentication middleware or token validation. The affected endpoints include GET /a2u/info, POST /a2u/subscribe, GET /a2u/events/{stream_name}, GET /a2u/events/sub/{id}, and GET /a2u/health. An attacker with network access to the A2U server can issue a simple unauthenticated POST /a2u/subscribe request to obtain a subscription_id, then connect to GET /a2u/events/sub/{subscription_id} to receive a continuous SSE stream of all agent events in real time. No credentials, tokens, or special privileges are required, and attack complexity is low (GitHub Advisory, PraisonAI Advisory).

Impact

Successful exploitation results in a high confidentiality impact: any network-accessible attacker can harvest all live agent activity in real time, including AI-generated responses, internal chain-of-thought reasoning, tool call names and arguments, and error details. This could expose sensitive business logic, proprietary data processed by agents, API keys or credentials passed as tool arguments, and user-facing outputs before they are delivered. There is no integrity or availability impact, but the data exposure risk is significant for organizations using PraisonAI to process sensitive or regulated information (GitHub Advisory).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-39889. The EPSS score is approximately 0.019% (6th percentile), indicating a low near-term exploitation probability (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires no authentication, no special tools, and only basic HTTP requests, making it trivially exploitable by any attacker with network access to the A2U server port.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible PraisonAI instances running version ≤ 4.5.114 using tools like Shodan, Censys, or nmap, targeting the A2U server port.
  2. Probe the info endpoint: Send GET /a2u/info without any authentication header to confirm the A2U server is present and enumerate available event stream names and event types (e.g., agent.started, agent.thinking, agent.tool_call, agent.response).
  3. Create a subscription: Send POST /a2u/subscribe (no auth token required) to the target server. The server responds with HTTP 200 and a JSON body containing a subscription_id (e.g., {"subscription_id":"sub-a1ad8a6edd8b","stream_name":"events","stream_url":"http://<target>/a2u/events/sub-a1ad8a6edd8b"}).
  4. Connect to the SSE stream: Send GET /a2u/events/sub/{subscription_id} to open a persistent SSE connection. The server streams all live agent events in real time.
  5. Harvest sensitive data: Collect and parse the SSE stream to extract agent responses, internal reasoning (agent.thinking), tool call names and arguments (agent.tool_call), and any sensitive data processed by the AI agents (GitHub Advisory, PraisonAI Advisory).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to /a2u/subscribe from external or unknown IP addresses; long-lived HTTP GET connections to /a2u/events/sub/{id} or /a2u/events/{stream_name} from unauthenticated clients; repeated unauthenticated requests to /a2u/info or /a2u/health.
  • Logs: Web server or application access logs showing unauthenticated 200-status responses to /a2u/subscribe, /a2u/info, /a2u/events/*, or /a2u/health endpoints from unexpected source IPs; high volume of SSE connection events in application logs.
  • Process/Application: Unusual spikes in active subscriptions or active streams as reported by the /a2u/health endpoint (active_subscriptions > expected count); SSE connections persisting for extended durations from non-application clients.

Mitigation and workarounds

The vendor has released PraisonAI version 4.5.115, which patches this vulnerability. Users should upgrade immediately from any version ≤ 4.5.114 to ≥ 4.5.115 via pip (pip install --upgrade praisonai) (PraisonAI Release). As a temporary workaround prior to upgrading, restrict network access to the A2U server port using firewall rules or network segmentation to prevent unauthenticated external access. Avoid exposing the A2U server directly to untrusted networks.

Community reactions

The vulnerability was reported by security researcher srisowmya2000 and published via GitHub's security advisory process (GitHub Advisory). Brief mentions appeared on Mastodon via @thehackerwire and on Bluesky, reflecting routine community tracking of the disclosure. No significant vendor statements beyond the advisory, nor major media coverage, have been identified.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management