Impact
PraisonAI’s authentication service defaults to a hard‑coded developer secret ('dev-secret-change-me') when the environment variable PLATFORM_JWT_SECRET is missing and runs with the default development guard (PLATFORM_ENV=dev). An unauthenticated attacker can create a signed JWT with any subject claim and the service will accept it as a legitimate identity. This enables direct impersonation of any user or workspace owner if the target’s identifier is known. The flaw is a classic authentication bypass (CWE‑287) coupled with insecure default configuration (CWE‑1188 and CWE‑798). The consequence is that an attacker can gain full access to privileged operations and data that belong to the impersonated account.
Affected Systems
The vulnerability affects PraisonAI’s open‑source platform distributed as praisonai-platform version 0.1.4 (and any earlier releases). The affected component is praisonai_platform/services/auth_service.py, which is part of the PraisonAI multi‑agent system. The problem is corrected in praisonai-platform version 0.1.6. All deployments running 0.1.4 or older on any environment that does not provide a custom JWT secret are susceptible.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. Although the EPSS score is reported as less than 1 %, meaning publicly observed exploitation is currently scarce, the vulnerability remains exploitable on any publicly reachable API endpoint that accepts JWTs. An attacker only needs the ability to construct a signed token and send it to the service; no authentication is required. This makes the attack relatively easy, especially in environments where the default developer secret is still active. The vulnerability is not currently listed in the CISA KEV catalog, but its high impact and the lack of a defensive fallback warrant immediate attention.
OpenCVE Enrichment
Github GHSA