{"id":"CVE-2026-44338","summary":"PraisonAI ships and generates a legacy API server with authentication disabled by default, allowing unauthenticated workflow execution","details":"PraisonAI is a multi-agent teams system. From version 2.5.6 to before version 4.6.34, PraisonAI ships a legacy Flask API server with authentication disabled by default. When that server is used, any caller that can reach it can access /agents and trigger the configured agents.yaml workflow through /chat without providing a token. This issue has been patched in version 4.6.34.","aliases":["GHSA-6rmh-7xcm-cpxj","PYSEC-2026-2904"],"modified":"2026-08-04T11:49:29.101540339Z","published":"2026-05-08T13:35:44.521Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-1188","CWE-306","CWE-668"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44338.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44338.json"},{"type":"ADVISORY","url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6rmh-7xcm-cpxj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44338"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mervinpraison/praisonai","events":[{"introduced":"98a4ff845029ca46d03ef5abf03b07096c2435f9"},{"fixed":"e5928449f73f66cc8af1de61621aa974ab255133"}],"database_specific":{"extracted_events":[{"introduced":"2.5.6"},{"fixed":"4.6.34"}],"source":"AFFECTED_FIELD"}}],"versions":["v4.6.33","v4.6.32","v4.6.31","v4.6.30","v4.6.29","v4.6.28","v4.6.27","v4.6.26","v4.6.25","v4.6.24","v4.6.23","v4.6.22","v4.6.21","v4.6.20","v4.6.19","v4.6.18","v4.6.16","v4.6.15","v4.6.14","v4.6.13","v4.6.12","v4.6.11","v4.6.10","v4.6.9","v4.5.149","v4.6.7","v4.6.6","v4.6.5","v4.6.4","v4.6.3","v4.6.2","v4.6.1","v4.5.148","v4.5.147","v4.5.146","v4.5.145","v4.5.144","v4.5.143","v4.5.140","v4.5.134","v4.5.133","v4.5.132","v4.5.131","v4.5.130","v4.5.129","v4.5.126","v4.5.128","v4.5.125","v4.5.124","v4.5.123","v4.5.122","v4.5.121","v4.5.120","v4.5.119","v4.5.118","v4.5.117","v4.5.115","v4.5.113","v4.5.112","v4.5.111","v4.5.110","v4.5.109","v4.5.108","v4.5.107","v4.5.106","v4.5.105","v4.5.104","v4.5.103","v4.5.102","v4.5.101","v4.5.100","v4.5.98","v4.5.96","v4.5.97","v4.5.95","v4.5.94","v4.5.93","v4.5.90","v4.5.88","v4.5.87","v4.5.85","v4.5.83","v4.5.82","v4.5.81","v4.5.80","v4.5.79","v4.5.78","v4.5.77","v4.5.76","v4.5.74","v4.5.73","v4.5.72","v4.5.71","v4.5.70","v4.5.69","v4.5.68","v4.5.67","v4.5.65","v4.5.64","v4.5.63","v4.5.62","v4.5.60","v4.5.59","v4.5.58","v4.5.57","v4.5.56","v4.5.55","v4.5.54","v4.5.52","v4.5.51","v4.5.49","v4.5.48","v4.5.46","v4.5.45","v4.5.44","v4.5.43","v4.5.42","v4.5.41","v4.5.40","v4.5.39","v4.5.38","v4.5.37","v4.5.36","v4.5.35","v4.5.34","v4.5.33","v4.5.32","v4.5.31","v4.5.30","v4.5.29","v4.5.28","v4.5.27","v4.5.26","v4.5.25","v4.5.24","v4.5.23","v4.5.22","v4.5.21","v4.5.20","v4.5.19","v4.5.18","v4.5.17","v4.5.16","v4.5.15","v4.5.14","v4.5.13","v4.5.12","v4.5.11","v4.5.10","v4.5.9","v4.5.8","v4.5.7","v4.5.6","v4.5.5","v4.5.3","v4.5.2","v4.5.1","v4.5.0","v4.4.12","v4.4.11","v4.4.10","v4.4.9","v4.4.8","v4.4.7","v4.4.6","v4.4.5","v0.2.0","praisonai@0.2.0","praisonai-derive@0.2.0","praisonai-cli@0.2.0","v2.8.0","v2.7.9","v2.7.8","v2.7.7","v2.7.6","v2.7.5","v2.7.4","v2.7.3","v2.7.2","v2.7.1","v2.7.0","v2.6.8","v2.6.7","v2.6.6","v2.6.5","v2.6.4","v2.6.3","v2.6.2","v2.6.1","v2.6.0","v2.5.7","v2.5.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44338.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"}]}