Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40289

32
FAUCET Score

OVERVIEW CVE-2026-40289 affects PraisonAI (versions below 4.5.139) and praisonaiagents (versions below 1.5.140). The vulnerability exists in the browser bridge WebSocket endpoint (/ws) which lacks proper authentication mechanisms and implements a bypassable origin check. An attacker can establish an unauthenticated connection and hijack active browser automation sessions by sending a start_session message, effectively taking control of connected browser extensions. SEVERITY This is a critical vulnerability with a CVSS score of 9.1, reflecting its network-based attack vector, low complexity, and lack of authentication or user interaction requirements. The server's default binding to 0.0.0.0 combined with the validation of Origin headers only when present creates a significant exposure. An attacker can achieve complete remote control of browser automation sessions, exfiltrate sensitive page context and automation results, and abuse model-backed browser actions in any environment where the bridge is network-accessible. EXPLOITATION STATUS Currently, there is no evidence of active exploitation in the wild, as this vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hot lists. No public exploit code appears to be widely available. However, the straightforward attack methodology and critical nature of the vulnerability warrant prompt patching to all affected systems, particularly those exposed on network interfaces.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.5.139CPE matchmatch criteria
cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:*
< 1.5.140CPE matchmatch criteria
cpe:2.3:a:praison:praisonaiagents:*:*:*:*:*:python:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.36%
Probability of exploitation in next 30 days
EPSS Percentile
28.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0036 is in the 6th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

pippatch availablevia ghsa
Product: praisonaiagentsFixed in: 1.5.140
pippatch availablevia ghsa
Product: PraisonAIFixed in: 4.5.139
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

pipGHSA-8x8f-54wf-vv92critical

PraisonAI Browser Server allows unauthenticated WebSocket clients to hijack connected extension sessions

Apr 10, 2026

References

github.com / MervinPraison/PraisonAI/security/advisories/GHSA-8x8f-54wf-vv92
ExploitVendor Advisory