CVE-2026-34952Disclosure(praison / praisonai)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch praison praisonai systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent topology at /info with no authentication. Any network client can connect, enumerate registered agents, and send arbitrary messages to agents and their tool sets. This issue has been patched in version 4.5.97.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonai

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-04-03); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
praisonai

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-03: 2Mentions · 2026-04-04: 1Mentions · 2026-04-06: 1Mentions · 2026-04-09: 1Patch / Workaround · 2026-04-03: 2Technical Details · 2026-04-03: 1Technical Details · 2026-04-04: 1Technical Details · 2026-04-06: 104-0304-0404-0604-09
Signal classification3 categories
Disclosure
360.0%
Patch
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-032
Disclosure1Patch1
2026-04-041
Disclosure1
2026-04-061
Disclosure1
2026-04-091
General1
Full discourse5 posts
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-34952: CRITICAL] PraisonAI Gateway server had a security vulnerability allowing unauthorized access. Update to version 4.5.97 to fix the issue and enhance cybersecurity. #cybersecurity#cve,CVE-2026-34952,#cybersecurity https://cvefind.com/CVE-2026-34952

    Post summary

    CVE-2026-34952 is a critical vulnerability in PraisonAI Gateway that permits unauthorized access. Users are advised to update to version 4.5.97 for remediation.

    0001054
    619 followersView on X
  • DailyCVE@dailycve
    General

    🔴 PraisonAI, Authentication Bypass, #CVE-2026-34952 (Critical) https://dailycve.com/praisonai-authentication-bypass-cve-2026-34952-critical/

    Post summary

    The post alerts about a critical authentication bypass CVE but offers no additional details, exploitation evidence, patches, or technical specifics.

    0000027
    178 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34952: PraisonAI: Missing Authenticatio... Wide-open WebSocket gateway lets anyone hijack AI agent clusters and execute arbitrary tool commands across the entire ... https://zerodaysignal.com/vulnerability/CVE-2026-34952 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-34952, revealing a missing authentication flaw in PraisonAI’s WebSocket gateway that permits unauthenticated hijacking of AI agent clusters and arbitrary command execution.

    0000056
    204 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-34952 - Critical PraisonAI is a multi-agent teams system. Prior to version 4.5.97, the PraisonAI Gateway server accepts WebSocket connections at /ws and serves agent topology at /info with no authenticati... https://www.thehackerwire.com/vulnerability/CVE-2026-34952/ https://t.co/dbd9XysEEN

    Post summary

    The post announces CVE‑2026‑34952 for PraisonAI Gateway, noting unauthenticated WebSocket and topology endpoints, but lacks PoC, exploit, patch, or active exploitation details.

    0000048
    164 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Missing authentication in `PraisonAI`'s WebSocket Gateway (CVE-2026-34952) allows unauthorized access. Review and implement strong authentication for all WebSocket connections. #PraisonAI #WebSockets #AuthBypass #infosec https://www.pulsepatch.io/posts/cve-2026-34952-praisonai-websocket-missing-authentication

    Post summary

    The tweet announces a missing authentication vulnerability (CVE-2026-34952) in PraisonAI's WebSocket Gateway, advises strengthening authentication, but does not provide PoC, exploit code, or evidence of active exploitation.

    0000026
    10 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonai---

Explore more