PraisonAI Open-source Proxy Framework Authentication Failed; Attackers Successful in Detection within 4 Hours
2026-09-30 19:56:58
According to CoinMeta, the open-source proxy framework PraisonAI was released without authentication enabled. Less than 4 hours after the announcement GitHub was published on May 11, 2026, at UTC time 13:56, attackers began conducting exploratory tests. This vulnerability was tracked as CVE-2026-44338 with a CVSS score of 7.3, which is classified as a classic CWE-306 (critical functionality lacking authentication) flaw. The root cause lies in the legacy Flask API server within the PrasionAI Python package. Affected versions range from 2.5.6 to 4.6.33, where variables auth_enabled and auth_token are hardcoded to false and none, respectively, causing the check_auth() function to return true by default, making authentication completely optional. Security teams should monitor requests to /agents and/or chat, especially those lacking an authorization header.
Source:Forkast
This content is for market information only and does not constitute investment advice.
Follow CoinMeta official accounts to stay updated

Hot Articles
Refresh

Bitcoin October 2026 Outlook: Can the 19% Historical Gain Hold?
9h ago

Dogecoin Price: Whales Buy $112M, Can DOGE Break $0.10?
09-29 12:48

What is Solidigm? Is Its $150B IPO Valuation a Bubble?
09-28 13:00

Is PAXG Stable? Is Gold-Backed Better Than Stablecoins?
09-24 18:04

ETH Rebounds to $2,800: Can It Hold $3,200 by Month-End?
09-23 11:07



