Description
PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents/{id}/invoke without CALL_SERVER_TOKEN authentication. Deployments that use the application's advertised opt-out can expose registered agents and their connected tools or private context to unauthenticated invocation. The vulnerability is fixed in 4.6.62.
Published: 2026-09-14
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Apply Patch
AI Analysis

Impact

Setting disabled causes the PRAISONAI application to unconditionally bypass token verification on the /api/v1/agents/{id}/invoke endpoint, allowing unauthenticated requests to invoke registered agents. This flaw can expose private context, connected tools, and other agent data to any party that can reach the endpoint, thereby compromising confidentiality and potentially enabling further malicious actions. The weakness is a classic case of Improper Authentication, reflected in CWE-287.

Affected Systems

The vulnerability affects installations of MervinPraison PraisonAI prior to version 4.6.62. Deployments that have configured the optional "PRAISONAI_CALL_AUTH=disabled" setting are impacted, while releases 4.6.62 and later contain the fix that restores proper authentication checks.

Risk and Exploitability

The flaw carries a CVSS score of 8.2, indicating a high severity. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, as any client able to reach the agent invocation API can exploit the flaw if the environment variable is set. Based on the description, it is inferred that the attack vector is remote network access. The exploitation is straightforward for applications that have opted to disable authentication, and no special system privilege is required.

Generated by OpenCVE AI on September 21, 2026 at 00:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update PraisonAI to release 4.6.62 or later, which restores proper authentication checks.
  • Remove or unset the PRAISONAI_CALL_AUTH=disabled environment variable to re‑enable the authentication guard.
  • Restrict network access to the /api/v1/agents/{id}/invoke endpoint or employ firewall rules to limit exposure to trusted hosts.

Generated by OpenCVE AI on September 21, 2026 at 00:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8ccj-p46r-jwqq PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication
History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents/{id}/invoke without CALL_SERVER_TOKEN authentication. Deployments that use the application's advertised opt-out can expose registered agents and their connected tools or private context to unauthenticated invocation. The vulnerability is fixed in 4.6.62.
Title PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:09:30.644Z

Reserved: 2026-06-24T00:33:17.708Z

Link: CVE-2026-57132

cve-icon Vulnrichment

Updated: 2026-09-16T15:09:23.594Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T16:17:14.860

Modified: 2026-09-16T16:17:13.090

Link: CVE-2026-57132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:45:08Z

Weaknesses