Unauthorized Browser Automation Vulnerability in PraisonAI by Mervin Praison
CVE-2026-55536
9.1CRITICAL
What is CVE-2026-55536?
PraisonAI, a multi-agent teams application, contains a vulnerability that permits unauthorized browser automation due to improper validation of Chrome extension origins. Specifically, the function _handle_connection() uses a flawed regex pattern that allows extra characters to be appended to the expected Chrome extension URL format. This oversight enables potential exploitation through start_session commands before the websocket.accept() method, creating a risk of unauthorized interactions with the server. Users are urged to update to version 4.6.58 or later to mitigate this security issue.
Affected Version(s)
PraisonAI < 4.6.58
