The SSE (Server-Sent Events) server in src/praisonai-agents/praisonaiagents/server/server.py exposes a /publish endpoint that broadcasts arbitrary messages to all connected clients without any authentication. The ServerConfig dataclass (line 24) defines an auth_token field, but this token is never validated in the /publish or /events request handlers. Any attacker with access to the SSE server port can inject arbitrary events into the SSE stream visible to all connected clients, or use /info to leak server configuration including connected client count.
Vulnerable code (lines 164–180):
async def publish(request):
try:
data = await request.json()
event_type = data.get("type", "message")
event_data = data.get("data", {})
self.broadcast(event_type, event_data)
return JSONResponse({
"success": True,
"clients": len(self._clients),
})
The auth_token field in ServerConfig (line 31):
@dataclass
class ServerConfig:
...
auth_token: Optional[str] = None
This auth_token is never referenced in any request handler. The /publish endpoint processes any POST request regardless of authentication headers. The /info endpoint (line 182) also has no auth and returns server configuration including self.config.to_dict().
Routes registration (lines 190–194):
routes = [
Route("/health", health, methods=["GET"]),
Route("/events", events, methods=["GET"]),
Route("/publish", publish, methods=["POST"]),
Route("/info", info, methods=["GET"]),
]
No authentication middleware or token validation is applied to any route.
Setup: Start the SSE server (default port 8765). This is the documented server mode for streaming agent events.
Positive trigger — unauthenticated event injection:
# From any network-reachable host:
curl -X POST http://localhost:8765/publish \
-H "Content-Type: application/json" \
-d '{"type": "message", "data": {"text": "INJECTED: arbitrary content sent to all clients"}}'
Expected response:
{"success": true, "clients": 3}
The response confirms the injection was broadcast to all connected SSE clients, and leaks the number of connected clients.
Positive trigger — info leak:
curl http://localhost:8765/info
Expected response:
{
"name": "PraisonAI Agent Server",
"version": "1.0.0",
"clients": 3,
"config": {
"host": "127.0.0.1",
"port": 8765,
"auth_token": "***",
...
}
}
Negative control — if auth were enforced:
A request without a valid Authorization: Bearer <token> header should return 401 Unauthorized. Currently, it returns 200 OK with no auth check.
Cleanup: No persistent changes.
An attacker with access to the SSE server port (default 8765, bound to 127.0.0.1 by default per DEFAULT_HOST at line 21) can:
/infoWhile the default binds to localhost, deployments in containers or cloud environments commonly override the host to 0.0.0.0 to allow external access. When the host is overridden, this is exploitable from the network without authentication.
auth_token in the /publish and /events handlers:async def publish(request):
token = request.headers.get("Authorization", "").replace("Bearer ", "")
if self.config.auth_token and token != self.config.auth_token:
return JSONResponse({"error": "Unauthorized"}, status_code=401)
# ... proceed with broadcast
Apply the same token validation to /events (for reading) and /info.
The default binding to 127.0.0.1 is appropriate; maintain this default and warn when overridden to 0.0.0.0.
Document the auth_token configuration option and recommend setting it in production.
| Software | From | Fixed in |
|---|---|---|
praisonaiagents
|
- | 1.6.59 |
A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.
CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.
A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.
Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.
Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.
SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.