CVE-2026-39889: PraisonAI has Unauthenticated SSE Event Stream Exposes All Agent Activity in A2U Server
PraisonAI is a multi-agent teams system. Prior to 4.5.115, the A2U (Agent-to-User) event stream server in PraisonAI exposes all agent activity without authentication. The createa2uroutes() function registers the following endpoints with NO authentication checks: /a2u/info, /a2u/subscribe, /a2u/events/{streamname}, /a2u/events/sub/{id}, and /a2u/health. This vulnerability is fixed in 4.5.115.
Other sources
The A2U (Agent-to-User) event stream server in PraisonAI exposes all agent activity without authentication. This is a separate component from the gateway server fixed in CVE-2026-34952.
The createa2uroutes() function registers the following endpoints with NO authentication checks: - GET /a2u/info — exposes server info and stream names - POST /a2u/subscribe — creates event stream subscription - GET /a2u/events/{streamname} — streams ALL agent events - GET /a2u/events/sub/{id} — streams events for subscription - GET /a2u/health — health check
An unauthenticated attacker can: 1. POST /a2u/subscribe → receive subscriptionid 2. GET /a2u/events/sub/{subscriptionid} → receive live SSE stream of all agent events including responses, tool calls, and thinking
This exposes sensitive agent activity including responses, internal reasoning, and tool call arguments to any network attacker.
<img width="1512" height="947" alt="image" src="https://github.com/user-attachments/assets/3438f3ea-75ec-4978-9dd9-d9a6da42c248" />
<img width="1512" height="571" alt="image" src="https://github.com/user-attachments/assets/ee3313f6-f522-48f7-9c06-e5e265c6aeb4" />
[1] POST /a2u/subscribe (no auth token) Status: 200 Response: {"subscriptionid":"sub-a1ad8a6edd8b","streamname":"events", "streamurl":"http://testserver/a2u/events/sub-a1ad8a6edd8b"} Got subscriptionid: sub-a1ad8a6edd8b
[2] GET /a2u/info (no auth token) Status: 200 Response: {"name":"A2U Event Stream","version":"1.0.0", "streams":["events"],"eventtypes":["agent.started","agent.thinking", "agent.toolcall","agent.response","agent.completed","agent.error"]}
[3] GET /a2u/health (no auth token) Status: 200 Response: {"status":"healthy","activesubscriptions":1,"activestreams":1}
Impact: Attacker can subscribe and receive ALL agent events including responses, tool calls, and internal reasoning in real-time
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/praisonaito a version that resolves this vulnerability.Fixed in 4.5.115 - Upgrade
Upgrade
PraisonAI A2U event stream serverto a version that resolves this vulnerability.Fixed in 4.5.115 - Compensating control
Restrict network access to PraisonAI’s A2U endpoints (/a2u/info, /a2u/subscribe, /a2u/health, /a2u/events/{stream_name}, /a2u/events/sub/{id}) so only trusted clients can reach them (e.g., via firewall/ACL).