Unauthorized Browser Automation Vulnerability in PraisonAI by Mervin Praison
CVE-2026-55536

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-55536?

PraisonAI, a multi-agent teams application, contains a vulnerability that permits unauthorized browser automation due to improper validation of Chrome extension origins. Specifically, the function _handle_connection() uses a flawed regex pattern that allows extra characters to be appended to the expected Chrome extension URL format. This oversight enables potential exploitation through start_session commands before the websocket.accept() method, creating a risk of unauthorized interactions with the server. Users are urged to update to version 4.6.58 or later to mitigate this security issue.

Affected Version(s)

PraisonAI < 4.6.58

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.