Description
PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup and token-issuance guards are disabled because PLATFORM_ENV also defaults to dev. An unauthenticated attacker can sign a JWT containing an attacker-chosen sub value, and AuthService._verify_token() accepts it as an authenticated identity, enabling user or workspace-owner impersonation when a target identifier is known. This vulnerability is fixed in praisonai-platform 0.1.6.
Published: 2026-09-15
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access via forged JWTs
Action: Immediate Patch
AI Analysis

Impact

PraisonAI’s authentication service defaults to a hard‑coded developer secret ('dev-secret-change-me') when the environment variable PLATFORM_JWT_SECRET is missing and runs with the default development guard (PLATFORM_ENV=dev). An unauthenticated attacker can create a signed JWT with any subject claim and the service will accept it as a legitimate identity. This enables direct impersonation of any user or workspace owner if the target’s identifier is known. The flaw is a classic authentication bypass (CWE‑287) coupled with insecure default configuration (CWE‑1188 and CWE‑798). The consequence is that an attacker can gain full access to privileged operations and data that belong to the impersonated account.

Affected Systems

The vulnerability affects PraisonAI’s open‑source platform distributed as praisonai-platform version 0.1.4 (and any earlier releases). The affected component is praisonai_platform/services/auth_service.py, which is part of the PraisonAI multi‑agent system. The problem is corrected in praisonai-platform version 0.1.6. All deployments running 0.1.4 or older on any environment that does not provide a custom JWT secret are susceptible.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity. Although the EPSS score is reported as less than 1 %, meaning publicly observed exploitation is currently scarce, the vulnerability remains exploitable on any publicly reachable API endpoint that accepts JWTs. An attacker only needs the ability to construct a signed token and send it to the service; no authentication is required. This makes the attack relatively easy, especially in environments where the default developer secret is still active. The vulnerability is not currently listed in the CISA KEV catalog, but its high impact and the lack of a defensive fallback warrant immediate attention.

Generated by OpenCVE AI on September 17, 2026 at 17:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the PraisonAI platform to version 0.1.6 or later, which removes the hard‑coded developer secret and restores proper token verification.
  • Configure the PLATFORM_JWT_SECRET environment variable with a secure, randomly generated key in all deployment environments so that JWTs cannot be forged with a known secret.
  • Set PLATFORM_ENV to 'production' to activate runtime guards, ensuring that any missing JWT secret triggers an error instead of falling back to the dev secret.

Generated by OpenCVE AI on September 17, 2026 at 17:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f38v-77qj-h4jq praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)
History

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup and token-issuance guards are disabled because PLATFORM_ENV also defaults to dev. An unauthenticated attacker can sign a JWT containing an attacker-chosen sub value, and AuthService._verify_token() accepts it as an authenticated identity, enabling user or workspace-owner impersonation when a target identifier is known. This vulnerability is fixed in praisonai-platform 0.1.6.
Title praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)
Weaknesses CWE-1188
CWE-287
CWE-798
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T17:45:28.460Z

Reserved: 2026-06-24T01:45:48.697Z

Link: CVE-2026-57148

cve-icon Vulnrichment

Updated: 2026-09-16T17:45:01.166Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:11.910

Modified: 2026-09-16T18:17:10.087

Link: CVE-2026-57148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default

  • CWE-287

    Improper Authentication

  • CWE-798

    Use of Hard-coded Credentials