Agents
PraisonAI CVE-2026-44338: Agent Framework Auth Bypass Exploited in 3 Hours 44 Minutes After Disclosure
CVE-2026-44338 (CVSS 7.3) in PraisonAI's legacy Flask API server ships with authentication disabled by default, allowing unauthenticated workflow execution and agent config enumeration. Sysdig documented the fastest observed exploit timeline: a scanner identifying as 'CVE-Detector/1.0' hit the vulnerable endpoint exactly 3 hours 44 minutes 39 seconds after the May 11 advisory. Patched in v4.6.34; affects versions 2.5.6 through 4.6.33. The speed of exploitation underscores that agent frameworks are now first-day targets.
↳ Follow the thread
No related signals yet.