Impact
PraisonAI’s Server‑Sent Events server fails to enforce the configured auth_token on the /publish, /events, and /info endpoints. As a result, any network client that can reach the SSE service can broadcast arbitrary events to connected clients and retrieve server configuration and client‑count information. This flaw allows an attacker to inject events and expose sensitive infrastructure details, constituting a flaw in authentication (CWE‑306).
Affected Systems
The vulnerability affects MervinPraison’s PraisonAI system, specifically the SSE server in src/praisonai-agents/praisonaiagents/server/server.py, for all releases prior to praisonaiagents version 1.6.58. Upgrading to 1.6.58 or later removes the unauthenticated access to /publish, /events, and /info endpoints.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑to‑moderate severity. The EPSS score is less than 1 %, implying a very low probability that this vulnerability will be exploited. It is not listed in the CISA KEV database. An attacker only needs network reach to the SSE endpoint; no additional privileges are required, but the risk is limited to environments where the SSE service is exposed to untrusted networks.
OpenCVE Enrichment
Github GHSA