Impact
PraisonAI is a multi‑agent collaboration platform. When an operator selects API‑key or JWT authentication, the recipe‑serve endpoint installs the corresponding middleware. However, if the required secret environment variable (PRAISONAI_API_KEY or PRAISONAI_JWT_SECRET) or the matching recipe value is not set, each middleware silently forwards all requests. This allows unauthenticated clients to access the recipe‑execution, input, and output APIs and can trigger connected tools even though authentication is ostensibly enabled.
Affected Systems
The affected product is PraisonAI, developed by MervinPraison. All versions of PraisonAI before the 4.6.58 release are vulnerable, as the fix was applied in that release. No other affected versions are specifically listed.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, and the EPSS score of <1 % suggests the likelihood of exploitation is currently low. Nonetheless, the weakness is remotely exploitable: any client that can reach the vulnerable API endpoints can bypass the authorization checks because the middleware forwards requests when secrets are missing. This allows unauthenticated callers to trigger recipe execution, submit inputs, retrieve outputs, and activate connected tools. The attack requires no prior authentication credential. While the exposure is low because the attack needs network access to the API and the secret variables unset, it is nonetheless a serious risk if the system is accessible from untrusted networks.
OpenCVE Enrichment
Github GHSA