Description
PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware forwards requests when PRAISONAI_API_KEY or PRAISONAI_JWT_SECRET and the corresponding recipe value are absent. Unauthenticated clients can then reach recipe execution, input, and output surfaces and may trigger connected tools despite the operator explicitly enabling authentication. This issue is fixed in 4.6.58.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass allowing unauthenticated access to recipe execution and tool triggers
Action: Immediate Patch
AI Analysis

Impact

PraisonAI is a multi‑agent collaboration platform. When an operator selects API‑key or JWT authentication, the recipe‑serve endpoint installs the corresponding middleware. However, if the required secret environment variable (PRAISONAI_API_KEY or PRAISONAI_JWT_SECRET) or the matching recipe value is not set, each middleware silently forwards all requests. This allows unauthenticated clients to access the recipe‑execution, input, and output APIs and can trigger connected tools even though authentication is ostensibly enabled.

Affected Systems

The affected product is PraisonAI, developed by MervinPraison. All versions of PraisonAI before the 4.6.58 release are vulnerable, as the fix was applied in that release. No other affected versions are specifically listed.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity, and the EPSS score of <1 % suggests the likelihood of exploitation is currently low. Nonetheless, the weakness is remotely exploitable: any client that can reach the vulnerable API endpoints can bypass the authorization checks because the middleware forwards requests when secrets are missing. This allows unauthenticated callers to trigger recipe execution, submit inputs, retrieve outputs, and activate connected tools. The attack requires no prior authentication credential. While the exposure is low because the attack needs network access to the API and the secret variables unset, it is nonetheless a serious risk if the system is accessible from untrusted networks.

Generated by OpenCVE AI on September 21, 2026 at 00:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PraisonAI to version 4.6.58 or later, where the middleware correctly enforces authentication when secrets are missing.
  • If upgrading is not immediately possible, explicitly set the PRAISONAI_API_KEY or PRAISONAI_JWT_SECRET environment variable, or otherwise block external access to the recipe execution or reverse proxy that restricts access to the recipe execution endpoints to trusted IP ranges or internal networks, effectively preventing unauthenticated access until the middleware can be correctly enforced.
  • Limit network access by configuring a firewall or reverse proxy to block unauthenticated requests to the recipe execution endpoints until the middleware is fixed or keys are set.

Generated by OpenCVE AI on September 21, 2026 at 00:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j4hj-7hfh-g2f4 praisonai: recipe serve auth middleware silently disables itself when no secret is set
History

Tue, 15 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware forwards requests when PRAISONAI_API_KEY or PRAISONAI_JWT_SECRET and the corresponding recipe value are absent. Unauthenticated clients can then reach recipe execution, input, and output surfaces and may trigger connected tools despite the operator explicitly enabling authentication. This issue is fixed in 4.6.58.
Title praisonai: recipe serve auth middleware silently disables itself when no secret is set
Weaknesses CWE-1188
CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T16:47:18.317Z

Reserved: 2026-06-24T00:33:17.707Z

Link: CVE-2026-57127

cve-icon Vulnrichment

Updated: 2026-09-14T16:47:09.085Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T16:17:13.557

Modified: 2026-09-16T13:42:48.053

Link: CVE-2026-57127

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:45:08Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default

  • CWE-306

    Missing Authentication for Critical Function