Authentication Bypass Vulnerability in PraisonAI by MervinPraison
CVE-2026-40116

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
9 April 2026

What is CVE-2026-40116?

The PraisonAI multi-agent teams system has a significant vulnerability in its call module where the /media-stream WebSocket endpoint accepts connections from any client without proper authentication or Twilio signature validation. This flaw allows unauthenticated attackers to establish connections that open authenticated sessions using the server's API key linked to OpenAI's Realtime API. As a result, attackers can exploit this vulnerability to overwhelm server resources, potentially depleting the victim's OpenAI API credits without any restrictions on the number of concurrent connections, message rate, or message size. The issue has been addressed in version 4.5.128.

Affected Version(s)

PraisonAI < 4.5.128

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.