Description
PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run when PLATFORM_ENV is also unset because that setting defaults to dev. A remote unauthenticated attacker can mint an HS256 token with an arbitrary sub and email, and the platform's AuthService._verify_token() and get_current_user dependency accept the forged identity for protected API routes. This vulnerability is fixed in praisonai-platform 0.1.6.
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Token forgery enabling unauthorized access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from a hard‑coded default JWT signing secret, "dev-secret-change-me", that is used when PLATFORM_JWT_SECRET is unset and the production guard is bypassed due to PLATFORM_ENV defaulting to dev. Because the signing key is predictable, any actor can forge an HS256 token with arbitrary sub and email claims. The platform’s AuthService._verify_token() and get_current_user dependency accept these forged tokens as valid, enabling attackers to impersonate users and access protected API routes. This flaw is aligned with CWE-798 and CWE-1188.

Affected Systems

The issue affects both PraisonAI and the praisonai-platform component before release 0.1.6. Users running MervinPraison PraisonAI or the praisonai-platform services with an earlier version, where PLATFORM_JWT_SECRET was not set and PLATFORM_ENV remained at its default, are vulnerable. Upgrading to version 0.1.6 or later eliminates the risk.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, but the EPSS score is under 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a low probability of current exploitation. Based on the description, an attacker can remotely forge JWTs by simply constructing an HS256 token, and can then access protected endpoints without any additional authentication. The vulnerability can be exploited with minimal effort and no external dependencies, making it an attractive target if the environment is misconfigured.

Generated by OpenCVE AI on September 17, 2026 at 17:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade praisonai-platform to version 0.1.6 or newer to replace the hard‑coded default secret.
  • Configure PLATFORM_JWT_SECRET with a strong, unique secret and set PLATFORM_ENV to prod to ensure the production guard is active.
  • Restrict access to the authentication service endpoints and monitor for unauthorized token usage.

Generated by OpenCVE AI on September 17, 2026 at 17:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-cwj8-7gp2-ggcw praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery
History

Thu, 17 Sep 2026 15:30:00 +0000


Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run when PLATFORM_ENV is also unset because that setting defaults to dev. A remote unauthenticated attacker can mint an HS256 token with an arbitrary sub and email, and the platform's AuthService._verify_token() and get_current_user dependency accept the forged identity for protected API routes. This vulnerability is fixed in praisonai-platform 0.1.6.
Title praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery
Weaknesses CWE-1188
CWE-798
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T14:18:35.600Z

Reserved: 2026-06-24T01:45:48.697Z

Link: CVE-2026-57147

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:11.760

Modified: 2026-09-17T15:16:48.603

Link: CVE-2026-57147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default

  • CWE-798

    Use of Hard-coded Credentials