OVERVIEW CVE-2026-40289 affects PraisonAI (versions below 4.5.139) and praisonaiagents (versions below 1.5.140). The vulnerability exists in the browser bridge WebSocket endpoint (/ws) which lacks proper authentication mechanisms and implements a bypassable origin check. An attacker can establish an unauthenticated connection and hijack active browser automation sessions by sending a start_session message, effectively taking control of connected browser extensions. SEVERITY This is a critical vulnerability with a CVSS score of 9.1, reflecting its network-based attack vector, low complexity, and lack of authentication or user interaction requirements. The server's default binding to 0.0.0.0 combined with the validation of Origin headers only when present creates a significant exposure. An attacker can achieve complete remote control of browser automation sessions, exfiltrate sensitive page context and automation results, and abuse model-backed browser actions in any environment where the bridge is network-accessible. EXPLOITATION STATUS Currently, there is no evidence of active exploitation in the wild, as this vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists. No public exploit code appears to be widely available. However, the straightforward attack methodology and critical nature of the vulnerability warrant prompt patching to all affected systems, particularly those exposed on network interfaces.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.139CPE matchmatch criteria | cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:* | ||
< 1.5.140CPE matchmatch criteria | cpe:2.3:a:praison:praisonaiagents:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.