CVE-2026-57128

MEDIUMPre-NVD 4.34.3
EchelonGraph scoreLOW confidence

This medium-severity CVE scores 4.3 under the CNA's CVSS (NVD's own analysis pending). EPSS exploit-prediction score not yet available (the EPSS model rescores nightly; freshly-published CVEs typically appear within 48 hours). GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).

Triggered by: NVD CVSS baseline
Sources: cna:github_m
4.3EG
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • Lower severity and no public exploit yet
CISA-KEV: Not listedEPSS PROB: CVSS: 4.3Exploit: None knownExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

PraisonAI: Unauthenticated Event Injection via SSE /publish Endpoint

Summary

The SSE (Server-Sent Events) server in src/praisonai-agents/praisonaiagents/server/server.py exposes a /publish endpoint that broadcasts arbitrary messages to all connected clients without any authentication. The ServerConfig dataclass (line 24) defines an auth_token field, but this token is never validated in the /publish or /events request handlers. Any attacker with access to the SSE server port can inject arbitrary events into the SSE stream visible to all connected clients, or use /info to leak server configuration including connected client count.

Details

Vulnerable code (lines 164–180):

async def publish(request):
    try:
        data = await request.json()
        event_type = data.get("type", "message")
        event_data = data.get("data", {})

self.broadcast(event_type, event_data)

return JSONResponse({ "success": True, "clients": len(self._clients), })

The auth_token field in ServerConfig (line 31):

@dataclass
class ServerConfig:
    ...
    auth_token: Optional[str] = None

This auth_token is never referenced in any request handler. The /publish endpoint processes any POST request regardless of authentication headers. The /info endpoint (line 182) also has no auth and returns server configuration including self.config.to_dict().

Routes registration (lines 190–194):

routes = [
    Route("/health", health, methods=["GET"]),
    Route("/events", events, methods=["GET"]),
    Route("/publish", publish, methods=["POST"]),
    Route("/info", info, methods=["GET"]),
]

No authentication middleware or token validation is applied to any route.

PoC

Setup: Start the SSE server (default port 8765). This is the documented server mode for streaming agent events.

Positive trigger — unauthenticated event injection:

# From any network-reachable host:
curl -X POST http://localhost:8765/publish \
  -H "Content-Type: application/json" \
  -d '{"type": "message", "data": {"text": "INJECTED: arbitrary content sent to all clients"}}'

Expected response:

{"success": true, "clients": 3}

The response confirms the injection was broadcast to all connected SSE clients, and leaks the number of connected clients.

Positive trigger — info leak:

curl http://localhost:8765/info

Expected response:

{
  "name": "PraisonAI Agent Server",
  "version": "1.0.0",
  "clients": 3,
  "config": {
    "host": "127.0.0.1",
    "port": 8765,
    "auth_token": "***",
    ...
  }
}

Negative control — if auth were enforced: A request without a valid Authorization: Bearer header should return 401 Unauthorized. Currently, it returns 200 OK with no auth check.

Cleanup: No persistent changes.

Impact

An attacker with access to the SSE server port (default 8765, bound to 127.0.0.1 by default per DEFAULT_HOST at line 21) can:

  • Inject arbitrary events into the SSE stream, potentially causing connected client applications to process malicious data, trigger actions, or display misleading content
  • Leak server configuration including number of connected clients and server settings via /info
  • Use the response to confirm connected client count, enabling reconnaissance

While the default binds to localhost, deployments in containers or cloud environments commonly override the host to 0.0.0.0 to allow external access. When the host is overridden, this is exploitable from the network without authentication.

Suggested remediation

  • Validate auth_token in the /publish and /events handlers:
async def publish(request):
    token = request.headers.get("Authorization", "").replace("Bearer ", "")
    if self.config.auth_token and token != self.config.auth_token:
        return JSONResponse({"error": "Unauthorized"}, status_code=401)
    # ... proceed with broadcast
  • Apply the same token validation to /events (for reading) and /info.
  • The default binding to 127.0.0.1 is appropriate; maintain this default and warn when overridden to 0.0.0.0.
  • Document the auth_token configuration option and recommend setting it in production.

CVSS v3
4.3
EG Score
4.3(low)
EG Risk
24(Track)
EG Risk 24/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity43% × 45%
Exploitation0% × 40%
Automatability30% × 15%
Action: Routine — remediate on your standard cadence.
EPSS PROB
EPSS %ILE
KEV
Not listed

Published

June 18, 2026

Last Modified

June 18, 2026

Vendor Advisories for CVE-2026-57128(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Affected Packages

(1 across 1 ecosystem)
PyPI(1)
PackageVulnerable rangeFixed inDependents
praisonaiagents0.0.1 ... 1.6.9 (586 versions)1.6.59

Data Freshness Timeline

(refreshed 3× in last 7d / 3× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-07-26 18:46 UTCEG score recompute
  2. 2026-07-23 03:20 UTCEG score recompute
  3. 2026-07-20 21:35 UTCEG score recompute

Frequently asked(4)

What is CVE-2026-57128?
CVE-2026-57128 is a medium vulnerability published on June 18, 2026. PraisonAI: Unauthenticated Event Injection via SSE /publish Endpoint Summary The SSE (Server-Sent Events) server in src/praisonai-agents/praisonaiagents/server/server.py exposes a /publish endpoint that broadcasts arbitrary messages to all connected clients without any authentication. The…
When was CVE-2026-57128 disclosed?
CVE-2026-57128 was first published in the National Vulnerability Database on June 18, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
What is the CVSS score of CVE-2026-57128?
CVE-2026-57128 has a CVSS v4.0 base score of 4.3 (CNA self-assessment; NVD's own analysis pending). The EG score is currently aggregating — additional source signals are being incorporated as they become available..
How do I remediate CVE-2026-57128?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-57128, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-57128

Explore →

Is Your Infrastructure Affected by CVE-2026-57128?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.