Authentication Bypass Vulnerability in PraisonAI by MervinPraison
CVE-2026-40116
7.5HIGH
What is CVE-2026-40116?
The PraisonAI multi-agent teams system has a significant vulnerability in its call module where the /media-stream WebSocket endpoint accepts connections from any client without proper authentication or Twilio signature validation. This flaw allows unauthenticated attackers to establish connections that open authenticated sessions using the server's API key linked to OpenAI's Realtime API. As a result, attackers can exploit this vulnerability to overwhelm server resources, potentially depleting the victim's OpenAI API credits without any restrictions on the number of concurrent connections, message rate, or message size. The issue has been addressed in version 4.5.128.
Affected Version(s)
PraisonAI < 4.5.128
