CVE-2026-34953
PraisonAI OAuthManager Authentication Bypass Vulnerability
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A flaw in PraisonAI's token validation allows unauthenticated access to its agent tools and capabilities by sending arbitrary bearer tokens. This could permit unauthorized control over system functionalities. The issue has been patched in version 4.5.97.