Impact
PraisonAI AgentOS used the default 0.0.0.0 binding and omitted authentication in its GET /api/agents and POST /api/chat endpoints from versions 1.6.0 through 1.7.2, exposing agent metadata and the ability to invoke any agent without credentials. This authentication bypass (CWE‑306) allows an attacker that can reach the service to retrieve agent names, roles, instruction prefixes, and to trigger agent operations that may access tools, memory, external APIs, credentials, and workflow state, potentially leading to arbitrary code execution or confidential data exposure.
Affected Systems
The affected product is PraisonAI by MervinPraison. Versions from 1.6.0 up to and including 1.7.2 are vulnerable. The vulnerability was fixed in release 1.7.2.
Risk and Exploitability
The CVSS base score is 9.4, classifying it as Critical. The EPSS score is less than 1%, indicating a low likelihood of exploitation for now, and it is not listed in CISA’s KEV catalog. The vulnerability is exploitable from any network location that can reach the AgentOS service, as no authentication middleware protects the affected endpoints.
OpenCVE Enrichment
Github GHSA