Beveiligingsadvies

CVE-2026-55536

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-25 15:21:53
Laatst bijgewerkt 2026-08-28 22:27:40
Toegewezen door GitHub_M
CVSS-score 9.1
Status PUBLISHED

Beschrijving

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome extension origins with re.match() and the unanchored expression chrome-extension://[a-z0-9]{32}. Extra trailing characters pass before websocket.accept(), allowing start_session commands and unauthorized browser automation. This issue is fixed in version 4.6.58.