Description
PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker-controlled prompts and agent configuration, list and read jobs, stream results, and cancel or delete other jobs, exposing service credentials and connected tool capabilities to unauthorized agent execution. This vulnerability is fixed in 4.6.58.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fq2m-6wqh-x44g | PraisonAI: Jobs API exposes agent-execution endpoints with no authentication |
References
History
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker-controlled prompts and agent configuration, list and read jobs, stream results, and cancel or delete other jobs, exposing service credentials and connected tool capabilities to unauthorized agent execution. This vulnerability is fixed in 4.6.58. | |
| Title | praisonai: Jobs API exposes agent-execution endpoints with no authentication | |
| Weaknesses | CWE-306 CWE-862 CWE-94 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-14T16:28:08.459Z
Reserved: 2026-06-24T00:33:17.708Z
Link: CVE-2026-57131
Updated: 2026-09-14T16:28:02.839Z
Status : Received
Published: 2026-09-14T16:17:14.710
Modified: 2026-09-14T17:17:48.970
Link: CVE-2026-57131
No data.
OpenCVE Enrichment
No data.
Github GHSA