
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39889 is a missing authentication vulnerability in the A2U (Agent-to-User) event stream server component of PraisonAI, an AI agent framework. The flaw allows unauthenticated network attackers to subscribe to and receive live Server-Sent Events (SSE) streams containing all agent activity, including responses, internal reasoning, and tool call arguments. It affects PraisonAI versions up to and including 4.5.114, and is a separate issue from the related gateway server vulnerability CVE-2026-34952. The vulnerability was published on April 7–8, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, PraisonAI Advisory).
The root cause is CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), stemming from the create_a2u_routes() function registering multiple API endpoints without any authentication middleware or token validation. The affected endpoints include GET /a2u/info, POST /a2u/subscribe, GET /a2u/events/{stream_name}, GET /a2u/events/sub/{id}, and GET /a2u/health. An attacker with network access to the A2U server can issue a simple unauthenticated POST /a2u/subscribe request to obtain a subscription_id, then connect to GET /a2u/events/sub/{subscription_id} to receive a continuous SSE stream of all agent events in real time. No credentials, tokens, or special privileges are required, and attack complexity is low (GitHub Advisory, PraisonAI Advisory).
Successful exploitation results in a high confidentiality impact: any network-accessible attacker can harvest all live agent activity in real time, including AI-generated responses, internal chain-of-thought reasoning, tool call names and arguments, and error details. This could expose sensitive business logic, proprietary data processed by agents, API keys or credentials passed as tool arguments, and user-facing outputs before they are delivered. There is no integrity or availability impact, but the data exposure risk is significant for organizations using PraisonAI to process sensitive or regulated information (GitHub Advisory).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-39889. The EPSS score is approximately 0.019% (6th percentile), indicating a low near-term exploitation probability (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the attack requires no authentication, no special tools, and only basic HTTP requests, making it trivially exploitable by any attacker with network access to the A2U server port.
GET /a2u/info without any authentication header to confirm the A2U server is present and enumerate available event stream names and event types (e.g., agent.started, agent.thinking, agent.tool_call, agent.response).POST /a2u/subscribe (no auth token required) to the target server. The server responds with HTTP 200 and a JSON body containing a subscription_id (e.g., {"subscription_id":"sub-a1ad8a6edd8b","stream_name":"events","stream_url":"http://<target>/a2u/events/sub-a1ad8a6edd8b"}).GET /a2u/events/sub/{subscription_id} to open a persistent SSE connection. The server streams all live agent events in real time.agent.thinking), tool call names and arguments (agent.tool_call), and any sensitive data processed by the AI agents (GitHub Advisory, PraisonAI Advisory)./a2u/subscribe from external or unknown IP addresses; long-lived HTTP GET connections to /a2u/events/sub/{id} or /a2u/events/{stream_name} from unauthenticated clients; repeated unauthenticated requests to /a2u/info or /a2u/health./a2u/subscribe, /a2u/info, /a2u/events/*, or /a2u/health endpoints from unexpected source IPs; high volume of SSE connection events in application logs./a2u/health endpoint (active_subscriptions > expected count); SSE connections persisting for extended durations from non-application clients.The vendor has released PraisonAI version 4.5.115, which patches this vulnerability. Users should upgrade immediately from any version ≤ 4.5.114 to ≥ 4.5.115 via pip (pip install --upgrade praisonai) (PraisonAI Release). As a temporary workaround prior to upgrading, restrict network access to the A2U server port using firewall rules or network segmentation to prevent unauthenticated external access. Avoid exposing the A2U server directly to untrusted networks.
The vulnerability was reported by security researcher srisowmya2000 and published via GitHub's security advisory process (GitHub Advisory). Brief mentions appeared on Mastodon via @thehackerwire and on Bluesky, reflecting routine community tracking of the disclosure. No significant vendor statements beyond the advisory, nor major media coverage, have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."