CVE-2026-34952
PraisonAI Has Missing Authentication in WebSocket Gateway
Summary
Remediation
Upgrade to the fixed version using your package manager.
pip install "praisonai>=4.5.97"
After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.
Affected Packages (1)
| Package | Ecosystem | Affected | Fixed In |
|---|---|---|---|
| praisonai | pypi | 0.0.1, 0.0.10, 0.0.11, 0.0.12 (+652 more) | 4.5.97 |
CVSS Score Breakdown
What the CVSS (Common Vulnerability Scoring System) 9.1 score means for each attack dimension.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
References
Frequently Asked Questions
- What is CVE-2026-34952?
- PraisonAI Has Missing Authentication in WebSocket Gateway This vulnerability has been assigned a severity rating of CRITICAL (CVSS score: 9.1/10).
- How do I check if my project is affected by CVE-2026-34952?
- CVE-2026-34952 affects praisonai. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-34952 and 200,000+ other known vulnerabilities.
Severity & Exploitability
Exploitation is straightforward and causes maximum impact. Patch immediately.
Also Known As
Related CVEs
- CVE-2026-40157CRITICAL
PraisonAI vulnerable to arbitrary file write via path traversal in `praisonai recipe unpack`
- CVE-2026-34934CRITICAL
PraisonAI Has Second-Order SQL Injection in `get_all_user_threads`
- CVE-2026-34935CRITICAL
PraisonAI: OS Command Injection in MCPHandler.parse_mcp_command()
- CVE-2026-44336CRITICAL
PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection
- CVE-2026-41497CRITICAL
PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection
- CVE-2026-57131CRITICAL
PraisonAI: Jobs API exposes agent-execution endpoints with no authentication
- CVE-2026-57127CRITICAL
praisonai: recipe serve auth middleware silently disables itself when no secret is set
- CVE-2026-57124CRITICAL
PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
Check if you're affected
Scan your dependencies to see if this vulnerability affects your projects.
Scan Your Dependencies