CVE-2026-34952
PraisonAI's Gateway server let anyone connect to its WebSocket endpoint and view agent topology without authentication. This allows an attacker to see which agents are registered and send arbitrary commands to them. The flaw was fixed in version 4.5.97.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
PraisonAI Gateway server, any installation running a version earlier than 4.5.97.
Real-world impact
An attacker could discover all agents in the system, send commands to them, and potentially disrupt or hijack their operations, leading to loss of confidentiality and integrity of the system.
Why this severity
The CVSS score of 9.1 reflects that the vulnerability can be exploited remotely with no authentication, giving the attacker full confidentiality and integrity impact on the system.
What to do about it
- 01Upgrade PraisonAI to version 4.5.97 or later.
- 02Restart the Gateway service.
NVD description
Timeline
- Apr 3, 2026 · Apr 3, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/MervinPraison/PraisonAI/sec…exploitvendor advisory