Impact
Setting disabled causes the PRAISONAI application to unconditionally bypass token verification on the /api/v1/agents/{id}/invoke endpoint, allowing unauthenticated requests to invoke registered agents. This flaw can expose private context, connected tools, and other agent data to any party that can reach the endpoint, thereby compromising confidentiality and potentially enabling further malicious actions. The weakness is a classic case of Improper Authentication, reflected in CWE-287.
Affected Systems
The vulnerability affects installations of MervinPraison PraisonAI prior to version 4.6.62. Deployments that have configured the optional "PRAISONAI_CALL_AUTH=disabled" setting are impacted, while releases 4.6.62 and later contain the fix that restores proper authentication checks.
Risk and Exploitability
The flaw carries a CVSS score of 8.2, indicating a high severity. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, as any client able to reach the agent invocation API can exploit the flaw if the environment variable is set. Based on the description, it is inferred that the attack vector is remote network access. The exploitation is straightforward for applications that have opted to disable authentication, and no special system privilege is required.
OpenCVE Enrichment
Github GHSA