CVE-2026-44338: PraisonAI Framework Actively Exploited Within Hours of Disclosure — No Auth Required
A critical authentication bypass flaw in PraisonAI’s legacy API server (CVE-2026-44338) shipped with auth disabled by default, allowing unauthenticated attackers to hijack AI workflows and drain API quotas. Active exploitation was observed within hours of public disclosure.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.