High-Risk PraisonAI Flaw Draws Hacker Scans Within Hours
PraisonAI is an open-source framework for collaboration among multiple AI agents. The legacy Flask API server in affected versions did not enable authentication by default, potentially allowing outsiders to access agent data, use chat functions or trigger workflows. The flaw creates risks of data leakage and misuse of LLM API quotas.
GitHub disclosed CVE-2026-44338 on May 11, 2026. The vulnerability carries a CVSS score of 7.3 and affects versions 2.5.6 through 4.6.33; it was patched in version 4.6.34. Cybersecurity company Sysdig found that hackers began scanning internet-exposed hosts just 3 hours and 44 minutes after disclosure.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.