Impact
The vulnerability arises from a hard‑coded default JWT signing secret, "dev-secret-change-me", that is used when PLATFORM_JWT_SECRET is unset and the production guard is bypassed due to PLATFORM_ENV defaulting to dev. Because the signing key is predictable, any actor can forge an HS256 token with arbitrary sub and email claims. The platform’s AuthService._verify_token() and get_current_user dependency accept these forged tokens as valid, enabling attackers to impersonate users and access protected API routes. This flaw is aligned with CWE-798 and CWE-1188.
Affected Systems
The issue affects both PraisonAI and the praisonai-platform component before release 0.1.6. Users running MervinPraison PraisonAI or the praisonai-platform services with an earlier version, where PLATFORM_JWT_SECRET was not set and PLATFORM_ENV remained at its default, are vulnerable. Upgrading to version 0.1.6 or later eliminates the risk.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, but the EPSS score is under 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a low probability of current exploitation. Based on the description, an attacker can remotely forge JWTs by simply constructing an HS256 token, and can then access protected endpoints without any additional authentication. The vulnerability can be exploited with minimal effort and no external dependencies, making it an attractive target if the environment is misconfigured.
OpenCVE Enrichment
Github GHSA