Mark RadarMARK RADAR
EN

High-Risk PraisonAI Flaw Draws Hacker Scans Within Hours

1 reports · First detected 2026-05-28 · Last active 2026-05-28

PraisonAI is an open-source framework for collaboration among multiple AI agents. The legacy Flask API server in affected versions did not enable authentication by default, potentially allowing outsiders to access agent data, use chat functions or trigger workflows. The flaw creates risks of data leakage and misuse of LLM API quotas.

GitHub disclosed CVE-2026-44338 on May 11, 2026. The vulnerability carries a CVSS score of 7.3 and affects versions 2.5.6 through 4.6.33; it was patched in version 4.6.34. Cybersecurity company Sysdig found that hackers began scanning internet-exposed hosts just 3 hours and 44 minutes after disclosure.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)