PraisonAI CVE-2026-44338: Multi-Agent Framework Auth Bypass Exploited Within 4 Hours of Disclosure
The Hacker News·high signal
CVE-2026-44338, a missing authentication vulnerability (CVSS 7.3) in PraisonAI's multi-agent orchestration framework, was actively exploited within 3 hours and 44 minutes of public disclosure on May 11. The flaw exposed /agents and /chat endpoints without any token requirement, allowing attackers to enumerate agent metadata and trigger agents.yaml workflows remotely. All versions from 2.5.6 through 4.6.33 were affected; patched in 4.6.34. The rapid exploitation timeline underscores the speed at which AI framework zero-days are now weaponized.