Description
PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the 0.0.0.0 default from src/praisonai-ts/src/os/config.ts and registers GET /api/agents and POST /api/chat without authentication middleware. A remote caller who can reach the service can obtain agent names, roles, and instruction prefixes and can invoke a selected agent, potentially reaching its tools, memory, external APIs, credentials, and workflow state. An initial remediation was released in version 1.7.2.
Published: 2026-09-15
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass with potential for remote code execution
Action: Immediate Patch
AI Analysis

Impact

PraisonAI AgentOS used the default 0.0.0.0 binding and omitted authentication in its GET /api/agents and POST /api/chat endpoints from versions 1.6.0 through 1.7.2, exposing agent metadata and the ability to invoke any agent without credentials. This authentication bypass (CWE‑306) allows an attacker that can reach the service to retrieve agent names, roles, instruction prefixes, and to trigger agent operations that may access tools, memory, external APIs, credentials, and workflow state, potentially leading to arbitrary code execution or confidential data exposure.

Affected Systems

The affected product is PraisonAI by MervinPraison. Versions from 1.6.0 up to and including 1.7.2 are vulnerable. The vulnerability was fixed in release 1.7.2.

Risk and Exploitability

The CVSS base score is 9.4, classifying it as Critical. The EPSS score is less than 1%, indicating a low likelihood of exploitation for now, and it is not listed in CISA’s KEV catalog. The vulnerability is exploitable from any network location that can reach the AgentOS service, as no authentication middleware protects the affected endpoints.

Generated by OpenCVE AI on September 17, 2026 at 17:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PraisonAI to version 1.7.2 or later to apply the official fix that adds authentication middleware to the agent endpoints.
  • Reconfigure the service binding so that AgentOS does not listen on 0.0.0.0; bind it to a specific internal interface or restrict it to localhost.
  • Implement network controls such as firewall rules or VPN gating to limit external access to the AgentOS API endpoints until a patch is applied.
  • Verify that the configuration file (config.ts) does not contain the default 0.0.0.0 address and remove any temporary credentials or debugging flags that may expose agent data.

Generated by OpenCVE AI on September 17, 2026 at 17:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9752-mhqh-h34f npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation
History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the 0.0.0.0 default from src/praisonai-ts/src/os/config.ts and registers GET /api/agents and POST /api/chat without authentication middleware. A remote caller who can reach the service can obtain agent names, roles, and instruction prefixes and can invoke a selected agent, potentially reaching its tools, memory, external APIs, credentials, and workflow state. An initial remediation was released in version 1.7.2.
Title PraisonAI AgentOS exposes unauthenticated agent listing and invocation
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T13:52:34.686Z

Reserved: 2026-06-24T01:45:48.696Z

Link: CVE-2026-57140

cve-icon Vulnrichment

Updated: 2026-09-15T13:30:36.475Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:11.473

Modified: 2026-09-15T14:45:28.563

Link: CVE-2026-57140

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function