CVE-2026-34952
Last modified
CVE-2026-34952 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent topology at /info with no authentication. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent topology at /info with no authentication. Any network client can connect, enumerate registered agents, and send arbitrary messages to agents and their tool sets. This issue has been patched in version 4.5.97.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Praison | Praisonai | < 4.5.97 |
References
- https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-cfh6-vr3j-qc3gExploit, Vendor Advisory
- https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-cfh6-vr3j-qc3gExploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-34952?
How severe is CVE-2026-34952?
How do I fix CVE-2026-34952?
Are you affected by CVE-2026-34952?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
