Impact
The flaw arises because PraisonAI mounts its job execution router under /api/v1/runs without enforcing authentication or per-job authorization. As a result, any network client that can reach this endpoint can submit arbitrary prompts and agent configurations, list, read, stream, cancel or delete jobs belonging to other users, and expose service credentials and tool capabilities. This missing authentication (CWE-306) and missing authorization (CWE-862) together with improper code generation input handling (CWE-94) can allow an attacker to inject code that executes within the agent environment, leading to remote code execution and potential compromise of internal secrets.
Affected Systems
All releases of PraisonAI from the vendor MervinPraison prior to version 4.6.58 are affected. The vulnerability is corrected in release 4.6.58, which restores authentication and authorization controls on the /api/v1/runs endpoints. The CVE affects the PraisonAI multi-agent teams system and its job execution API.
Risk and Exploitability
The CVSS score is 9.8, classifying the issue as critical. The EPSS score is less than 1%, indicating a very low but nonzero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the /api/v1/runs endpoint is network exposed and lacks authentication, any attacker who can reach the server can trigger the flaw, potentially executing arbitrary code and exfiltrating service credentials. The combination of high severity and network access makes this vulnerability highly actionable.
OpenCVE Enrichment
Github GHSA