HomeSecurityNew vulnerability in PraisonAI: Targeting a few hours after disclosure

New vulnerability in PraisonAI: Targeting a few hours after disclosure

The speed with which cybercriminals are exploiting new vulnerabilities continues to worry the cybersecurity industry. This time, the target was PraisonAI, an open-source AI orchestration framework, which is affected by a significant security flaw that allows authentication bypass. According to Sysdig, web crawlers began searching for vulnerable installations less than four hours after the issue was publicly disclosed.

PrisonAI

The vulnerability, listed as CVE-2026-44338, affects an older Flask-based API server component of PraisonAI and affects versions 2.5.6 through 4.6.33. The issue has already been fixed in version 4.6.34, but experts warn that many affected installations remain unpatched.

The problem starts with a dangerous default

At the heart of the vulnerability is a design choice that the researchers describe as a “security anti-pattern.” PraisonAI’s legacy API server had authentication disabled by default, with the settings “AUTH_ENABLED = False” and “AUTH_TOKEN = None” effectively allowing unauthenticated access.

See also: NGINX Rift: Critical 18-year-old vulnerability allows RCE without authentication

This means that anyone who could connect to exposed PraisonAI services could interact with agent workflows without requiring valid credentials. While the vulnerability does not directly lead to remote code execution, experts emphasize that the real risk depends on the permissions granted to the AI ​​workflows.

The explosive rise of AI agents creates new attack surfaces

The incident highlights a broader problem that is starting to appear more and more frequently: many businesses are adopting AI agents and automated workflows at great speed, without implementing the same levels of security that they would require in traditional enterprise applications.

Trey Ford highlighted that many organizations have yet to assess the true risk of exposing AI services to the internet. He explains that when AI agents gain access to APIs, cloud resources, credentials, or corporate data, a simple authentication bypass can escalate into a serious breach.

The situation becomes even more worrying when considering that AI orchestration frameworks often act as the “central brains” of automated systems, gaining access rights to critical infrastructure functions.

See also: New YellowKey vulnerability bypasses BitLocker

New vulnerability in PraisonAI: Targeting a few hours after disclosure

The attacks began almost immediately

Sysdig revealed that the first detection of suspicious activity was recorded just three hours and 44 minutes after the advisory on GitHub. Initially, scans targeted general paths such as “/.env” and “/admin”, before quickly switching to specific PraisonAI endpoints.

Attackers were looking for endpoints such as “/api/agents”, “/api/agents/config”, “/docs” and “/praisonai/version.txt”, indicating that there was already an understanding of the framework’s structure. The speed of this transition confirms that zero-day and newly disclosed vulnerabilities are now being incorporated almost immediately into automated detection and exploitation tools.

The real risk for organizations and AI infrastructures

The researchers point out that the problem is not limited to authentication bypass. If AI agents have access to cloud functions, files, pipelines, or automation services, an unauthorized user can trigger workflows that perform critical tasks on behalf of the organization.

In some scenarios, this could lead to access to sensitive data, script execution, credential leakage , or even chain attacks on other services. The increasing interconnection of AI agents with DevOps and cloud environments means that such vulnerabilities are becoming increasingly important.

See also: Fragnesia: New Linux kernel vulnerability provides root access

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

New vulnerability in PraisonAI: Targeting a few hours after disclosure

Safety recommendations and immediate actions

Sysdig urges organizations to immediately upgrade to version 4.6.34 or later, which has removed the problematic legacy behavior. It is also recommended to completely abandon the old “api_server.py” as it remains high-risk.

Experts also recommend monitoring suspicious requests that use the “CVE-Detector/1.0” user-agent, as well as increased surveillance on endpoints such as “/agents,” “/chat,” and “/api/agents.” Because authentication bypassing leaves no visible traces in application logs, monitoring at the network level is considered critical.

The PraisonAI incident serves as yet another reminder that AI systems must now be treated as fully productive, high-value infrastructure. As the adoption of AI agents accelerates globally, cybersecurity is becoming a key survival factor for any organization investing in automation and AI.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS