Description
PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker-controlled prompts and agent configuration, list and read jobs, stream results, and cancel or delete other jobs, exposing service credentials and connected tool capabilities to unauthorized agent execution. This vulnerability is fixed in 4.6.58.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution via unauthenticated agent‑execution endpoints
Action: Immediate patch
AI Analysis

Impact

The flaw arises because PraisonAI mounts its job execution router under /api/v1/runs without enforcing authentication or per-job authorization. As a result, any network client that can reach this endpoint can submit arbitrary prompts and agent configurations, list, read, stream, cancel or delete jobs belonging to other users, and expose service credentials and tool capabilities. This missing authentication (CWE-306) and missing authorization (CWE-862) together with improper code generation input handling (CWE-94) can allow an attacker to inject code that executes within the agent environment, leading to remote code execution and potential compromise of internal secrets.

Affected Systems

All releases of PraisonAI from the vendor MervinPraison prior to version 4.6.58 are affected. The vulnerability is corrected in release 4.6.58, which restores authentication and authorization controls on the /api/v1/runs endpoints. The CVE affects the PraisonAI multi-agent teams system and its job execution API.

Risk and Exploitability

The CVSS score is 9.8, classifying the issue as critical. The EPSS score is less than 1%, indicating a very low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the /api/v1/runs endpoint is network exposed and lacks authentication, any attacker who can reach the server can trigger the flaw, potentially executing arbitrary code and exfiltrating service credentials. The combination of high severity and network access makes this vulnerability highly actionable.

Generated by OpenCVE AI on September 21, 2026 at 00:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PraisonAI to version 4.6.58 or later, where authentication and authorization controls are restored.
  • If upgrading is not possible immediately, restrict network access to the /api/v1/runs endpoint by configuring firewalls or host-based access control lists so that only trusted internal hosts can reach the API.
  • As a temporary workaround, disable the agent-execution endpoints via a reverse-proxy or application configuration until the patch is applied.
  • Monitor API traffic for anomalous requests that may indicate exploitation attempts.

Generated by OpenCVE AI on September 21, 2026 at 00:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fq2m-6wqh-x44g PraisonAI: Jobs API exposes agent-execution endpoints with no authentication
History

Tue, 15 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker-controlled prompts and agent configuration, list and read jobs, stream results, and cancel or delete other jobs, exposing service credentials and connected tool capabilities to unauthorized agent execution. This vulnerability is fixed in 4.6.58.
Title praisonai: Jobs API exposes agent-execution endpoints with no authentication
Weaknesses CWE-306
CWE-862
CWE-94
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T16:28:08.459Z

Reserved: 2026-06-24T00:33:17.708Z

Link: CVE-2026-57131

cve-icon Vulnrichment

Updated: 2026-09-14T16:28:02.839Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T16:17:14.710

Modified: 2026-09-16T13:42:48.070

Link: CVE-2026-57131

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:15:06Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-862

    Missing Authorization

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')