CVE-2026-40289Disclosure(praison / praisonai)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch praison praisonai systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser start) is vulnerable to unauthenticated remote session hijacking due to missing authentication and a bypassable origin check on its /ws WebSocket endpoint. The server binds to 0.0.0.0 by default and only validates the Origin header when one is present, meaning any non-browser client that omits the header is accepted without restriction. An unauthenticated network attacker can connect, send a start_session message, and the server will route it to the first idle browser-extension WebSocket (effectively hijacking that session) and then broadcast all resulting automation actions and outputs back to the attacker. This enables unauthorized remote control of connected browser automation sessions, leakage of sensitive page context and automation results, and misuse of model-backed browser actions in any environment where the bridge is network-reachable. This issue has been fixed in versions 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • praisonai
  • praisonaiagents

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 5 mentions (2026-04-14); latest day: 2
  • 7 total mentions across 2 days

Affected systems

Vendors
Products
praisonaipraisonaiagents

Deep dive

Activity timeline7 mentions / 2d
01345Mentions · 2026-04-14: 5Mentions · 2026-04-15: 2PoC Mentioned / Linked · 2026-04-14: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-04-14: 3Technical Details · 2026-04-15: 204-1404-15
Signal classification3 categories
Disclosure
571.4%
General
114.3%
Patch
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-145
Disclosure3General1Patch1
2026-04-152
Disclosure2
Full discourse7 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    `PraisonAI Browser Server` is vulnerable to unauthenticated WebSocket session hijacking (CVE-2026-40289), potentially compromising browser extensions. Restrict network access. #AppSec #CyberSecurity https://www.pulsepatch.io/posts/cve-2026-40289-praisonai-browser-server-websocket-hijack

    Post summary

    The post announces CVE‑2026‑40289 as an unauthenticated WebSocket session hijack vulnerability in PraisonAI Browser Server and recommends restricting network access as a workaround.

    20010149
    12 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple critical vulnerabilities in #PraisonAI CVE-2026-40313, CVE-2026-40288, CVE-2026-40289. These vulnerabilities could enable system compromise, data exposure, or full takeover. Updates are available. #Patch #Patch #Patch

    Post summary

    The message alerts about three critical CVEs in PraisonAI and notes that patches are available.

    00001190
    7.2K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-40289 📊 Severity: 9.1 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-40289 #CVE-2026-40289 #CVE #Critical #CyberSecurity #InfoSec https://t.co/O4bp6kMPbs

    Post summary

    The tweet announces a new critical vulnerability (CVE-2026-40289) with a CVSS score of 9.1, but offers no additional technical specifics, PoC, or patch information.

    0000029
    137 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40289: PraisonAI Browser Server allows ... Network-exposed WebSocket with zero auth + bypassable Origin check = instant browser session takeover for any attacker ... https://zerodaysignal.com/vulnerability/CVE-2026-40289 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-40289 exposes a network‑exposed WebSocket in PraisonAI Browser Server with zero authentication and bypassable Origin checks, allowing instant browser session takeover. A threat alert posts a link for details, but no patch, active exploitation, or exploit code is reported.

    0000060
    218 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40289 PraisonAI is a multi-agent teams system. In versions below 4.5.139 of PraisonAI and 1.5.140 of praisonaiagents, the browser bridge (praisonai browser start) is vulner… https://www.cve.org/CVERecord?id=CVE-2026-40289

    Post summary

    The post merely references CVE‑2026‑40289 and indicates a browser bridge issue in certain PraisonAI versions, but offers no additional technical detail or actionable information.

    0000046
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40289 Unauthenticated Remote Session Hijacking in PraisonAI Browser Bridge Below 4.5.139 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40289

    Post summary

    A newly identified unauthenticated remote session hijacking vulnerability exists in PraisonAI Browser Bridge versions below 4.5.139.

    0000039
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-40289: CRITICAL] Security alert: PraisonAI versions <4.5.139 & praisonaiagents versions <1.5.140 are vulnerable to unauthenticated remote session hijacking due to missing authentication. Issue reso...#cve,CVE-2026-40289,#cybersecurity https://cvefind.com/CVE-2026-40289

    Post summary

    A security alert announces CVE‑2026‑40289, noting that un‑authenticated remote session hijacking is possible in PraisonAI <4.5.139 and praisonaiagents <1.5.140, but no PoC, exploit, active use, or patch details are provided.

    0000042
    620 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apppraisonpraisonai---
Apppraisonpraisonaiagents-python-

Explore more