GHSA-35w5-pcw4-jx94: praisonaiagents: unauth SSE endpoint enables event injection

GHSA-35w5-pcw4-jx94 MEDIUM
Published June 18, 2026
CISO Take

PraisonAI Agents ships an SSE server with a /publish endpoint that accepts event broadcasts and a /info endpoint that returns server configuration — both with zero authentication, despite an auth_token field existing in the ServerConfig dataclass that is never checked. While the default binding is localhost, any container or cloud deployment that sets host to 0.0.0.0 (a common operational pattern) exposes this to the network, making exploitation a single unauthenticated curl command. The package carries 46 CVEs, signaling systemic security debt, and 11 downstream dependents that inherit the exposure. Upgrade to praisonaiagents 1.6.59 immediately; if patching is delayed, firewall port 8765 and audit all deployments for host=0.0.0.0 overrides.

Sources: GitHub Advisory ATLAS

What is the risk?

Medium severity (CVSS 4.3, AV:A) in default localhost configuration, escalating to effectively network-accessible in container and cloud deployments that override host to 0.0.0.0. Exploitation requires no credentials, no special knowledge, and no user interaction. The presence of an unused auth_token field in ServerConfig confirms intentional-but-unimplemented authentication — a developer oversight rather than a design decision, making the vulnerability unambiguous. Not in CISA KEV, no public exploit tooling, but exploit complexity is trivial.

How does the attack unfold?

Reconnaissance
Attacker queries the unauthenticated /info endpoint to confirm the SSE server is active, enumerate connected client count, and extract server configuration including host and port bindings.
AML.T0006
Initial Access
Attacker sends an unauthenticated POST request to /publish endpoint on the SSE server, bypassing the non-existent authentication check with a crafted event payload.
AML.T0049
Context Poisoning
Malicious event payload is broadcast simultaneously to all connected SSE clients, injecting adversary-controlled data into the AI agent orchestration stream trusted by downstream consumers.
AML.T0080
Impact
Connected AI agent clients process injected events, enabling unintended tool invocations, agent state corruption, suppression of legitimate alerts, or downstream prompt injection if event data feeds an LLM context.
AML.T0053

What systems are affected?

Package Ecosystem Vulnerable Range Patched
PraisonAI Agents pip <= 1.6.48 1.6.59
11 dependents 65% patched ~6d to patch Full package profile →

Do you use PraisonAI Agents? You're affected.

How severe is it?

CVSS 3.1
4.3 / 10
EPSS
N/A
Exploitation Status
No known exploitation
Sophistication
Trivial

What is the attack surface?

AV AC PR UI S C I A
AV Adjacent
AC Low
PR None
UI None
S Unchanged
C None
I Low
A None

What should I do?

6 steps
  1. Upgrade praisonaiagents to >= 1.6.59 which patches the missing auth_token validation in /publish, /events, and /info handlers.

  2. If immediate patching is not possible, restrict access to SSE server port 8765 via host firewall rules or network ACLs.

  3. Audit all deployments for host overrides to 0.0.0.0 — treat any such deployment as fully network-exposed until patched.

  4. Post-patch, verify ServerConfig instantiation sets a strong auth_token and confirm Authorization: Bearer headers are enforced.

  5. Monitor access logs for unexpected POST requests to /publish or unauthenticated GET requests to /info from non-local sources.

  6. Apply network segmentation to AI agent infrastructure to contain blast radius if future vulnerabilities emerge.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Art. 15 - Accuracy, robustness and cybersecurity
ISO 42001
A.9.1 - Information security controls for AI systems
NIST AI RMF
GOVERN 6.2 - Organizational teams and individuals are committed to AI risk management
OWASP LLM Top 10
LLM08:2025 - Excessive Agency

Frequently Asked Questions

What is GHSA-35w5-pcw4-jx94?

PraisonAI Agents ships an SSE server with a /publish endpoint that accepts event broadcasts and a /info endpoint that returns server configuration — both with zero authentication, despite an auth_token field existing in the ServerConfig dataclass that is never checked. While the default binding is localhost, any container or cloud deployment that sets host to 0.0.0.0 (a common operational pattern) exposes this to the network, making exploitation a single unauthenticated curl command. The package carries 46 CVEs, signaling systemic security debt, and 11 downstream dependents that inherit the exposure. Upgrade to praisonaiagents 1.6.59 immediately; if patching is delayed, firewall port 8765 and audit all deployments for host=0.0.0.0 overrides.

Is GHSA-35w5-pcw4-jx94 actively exploited?

No confirmed active exploitation of GHSA-35w5-pcw4-jx94 has been reported, but organizations should still patch proactively.

How to fix GHSA-35w5-pcw4-jx94?

1. Upgrade praisonaiagents to >= 1.6.59 which patches the missing auth_token validation in /publish, /events, and /info handlers. 2. If immediate patching is not possible, restrict access to SSE server port 8765 via host firewall rules or network ACLs. 3. Audit all deployments for host overrides to 0.0.0.0 — treat any such deployment as fully network-exposed until patched. 4. Post-patch, verify ServerConfig instantiation sets a strong auth_token and confirm Authorization: Bearer headers are enforced. 5. Monitor access logs for unexpected POST requests to /publish or unauthenticated GET requests to /info from non-local sources. 6. Apply network segmentation to AI agent infrastructure to contain blast radius if future vulnerabilities emerge.

What systems are affected by GHSA-35w5-pcw4-jx94?

This vulnerability affects the following AI/ML architecture patterns: agent frameworks, multi-agent orchestration systems, AI pipeline monitoring and observability layers, real-time AI event streaming infrastructure.

What is the CVSS score for GHSA-35w5-pcw4-jx94?

GHSA-35w5-pcw4-jx94 has a CVSS v3.1 base score of 4.3 (MEDIUM).

What is the AI security impact?

Affected AI Architectures

agent frameworksmulti-agent orchestration systemsAI pipeline monitoring and observability layersreal-time AI event streaming infrastructure

MITRE ATLAS Techniques

AML.T0006 Active Scanning
AML.T0049 Exploit Public-Facing Application
AML.T0080 AI Agent Context Poisoning
AML.T0084 Discover AI Agent Configuration

Compliance Controls Affected

EU AI Act: Art. 15
ISO 42001: A.9.1
NIST AI RMF: GOVERN 6.2
OWASP LLM Top 10: LLM08:2025

What are the technical details?

Original Advisory

## Summary The SSE (Server-Sent Events) server in `src/praisonai-agents/praisonaiagents/server/server.py` exposes a `/publish` endpoint that broadcasts arbitrary messages to all connected clients without any authentication. The `ServerConfig` dataclass (line 24) defines an `auth_token` field, but this token is never validated in the `/publish` or `/events` request handlers. Any attacker with access to the SSE server port can inject arbitrary events into the SSE stream visible to all connected clients, or use `/info` to leak server configuration including connected client count. ## Details **Vulnerable code (lines 164–180):** ```python async def publish(request): try: data = await request.json() event_type = data.get("type", "message") event_data = data.get("data", {}) self.broadcast(event_type, event_data) return JSONResponse({ "success": True, "clients": len(self._clients), }) ``` The `auth_token` field in `ServerConfig` (line 31): ```python @dataclass class ServerConfig: ... auth_token: Optional[str] = None ``` This `auth_token` is **never referenced** in any request handler. The `/publish` endpoint processes any POST request regardless of authentication headers. The `/info` endpoint (line 182) also has no auth and returns server configuration including `self.config.to_dict()`. **Routes registration (lines 190–194):** ```python routes = [ Route("/health", health, methods=["GET"]), Route("/events", events, methods=["GET"]), Route("/publish", publish, methods=["POST"]), Route("/info", info, methods=["GET"]), ] ``` No authentication middleware or token validation is applied to any route. ## PoC **Setup:** Start the SSE server (default port 8765). This is the documented server mode for streaming agent events. **Positive trigger — unauthenticated event injection:** ```bash # From any network-reachable host: curl -X POST http://localhost:8765/publish \ -H "Content-Type: application/json" \ -d '{"type": "message", "data": {"text": "INJECTED: arbitrary content sent to all clients"}}' ``` **Expected response:** ```json {"success": true, "clients": 3} ``` The response confirms the injection was broadcast to all connected SSE clients, and leaks the number of connected clients. **Positive trigger — info leak:** ```bash curl http://localhost:8765/info ``` **Expected response:** ```json { "name": "PraisonAI Agent Server", "version": "1.0.0", "clients": 3, "config": { "host": "127.0.0.1", "port": 8765, "auth_token": "***", ... } } ``` **Negative control — if auth were enforced:** A request without a valid `Authorization: Bearer <token>` header should return 401 Unauthorized. Currently, it returns 200 OK with no auth check. **Cleanup:** No persistent changes. ## Impact An attacker with access to the SSE server port (default 8765, bound to `127.0.0.1` by default per `DEFAULT_HOST` at line 21) can: - **Inject arbitrary events** into the SSE stream, potentially causing connected client applications to process malicious data, trigger actions, or display misleading content - **Leak server configuration** including number of connected clients and server settings via `/info` - **Use the response** to confirm connected client count, enabling reconnaissance While the default binds to localhost, deployments in containers or cloud environments commonly override the host to `0.0.0.0` to allow external access. When the host is overridden, this is exploitable from the network without authentication. ## Suggested remediation 1. **Validate `auth_token`** in the `/publish` and `/events` handlers: ```python async def publish(request): token = request.headers.get("Authorization", "").replace("Bearer ", "") if self.config.auth_token and token != self.config.auth_token: return JSONResponse({"error": "Unauthorized"}, status_code=401) # ... proceed with broadcast ``` 2. Apply the same token validation to `/events` (for reading) and `/info`. 3. The default binding to `127.0.0.1` is appropriate; maintain this default and warn when overridden to `0.0.0.0`. 4. Document the `auth_token` configuration option and recommend setting it in production.

Exploitation Scenario

An attacker targeting a cloud-deployed PraisonAI Agents instance first sends an unauthenticated GET to /info to confirm the SSE server is active, extract the connected client count, and enumerate server configuration — zero credentials required. With the deployment confirmed, they craft a malicious event payload mimicking legitimate agent status messages and POST it to /publish. The injection is immediately broadcast to all connected SSE consumers: monitoring dashboards, downstream agent orchestrators, or user-facing applications processing agent outputs. A targeted payload could inject false task-completion signals to suppress alerts, feed adversary-controlled parameters into agent tool invocations, or embed prompt injection payloads into the event stream consumed by a downstream LLM agent that trusts SSE data as authoritative.

Weaknesses (CWE)

CWE-306 — Missing Authentication for Critical Function: The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

  • [Architecture and Design] Divide the software into anonymous, normal, privileged, and administrative areas. Identify which of these areas require a proven user identity, and use a centralized authentication capability. Identify all potential communication channels, or other means of interaction with the software, to ensure that all channels are appropriately protected, including those channels that are assumed to be accessible only by authorized parties. Developers sometimes perform authentication at the primary channel, but open up a secondary channel that is assumed to be private. For example, a login mechanism may be listening on one network port, but after successful authentication, it may open up a second port where it waits for the connection, but avoids authentication because it assumes that only the authenticated party will connect to the port. In general, if the software or protocol allows a single session or user state to persist across multiple connections or channels, authentication and appropriate
  • [Architecture and Design] For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Timeline

Published
June 18, 2026
Last Modified
June 18, 2026
First Seen
June 18, 2026

Related Vulnerabilities