
CVE-2026-39889 PraisonAI is a multi-agent teams system. Prior to 4.5.115, the A2U (Agent-to-User) event stream server in PraisonAI exposes all agent activity without authentication.… https://www.cve.org/CVERecord?id=CVE-2026-39889
Post summary
CVE-2026-39889 reveals that PraisonAI versions prior to 4.5.115 expose all agent activity via the A2U event stream server without authentication, indicating an unauthenticated data exposure.

