PraisonAI’s Open-Source Agent Framework Shipped With Auth Disabled — Attackers Probed It in Under 4 Hours
On May 11, 2026, at 13:56 UTC, a GitHub advisory was published detailing a critical vulnerability in the PraisonAI multi-agent orchestration framework. Exactly 3 hours, 44 minutes, and 39 seconds later, the first targeted probe hit a vulnerable instance. The vulnerability, tracked as CVE-2026-44338, carries a CVSS score of 7.3. It is a classic CWE-306…