Impact
PraionAI versions earlier than 1.7.3 expose an insecure default configuration. The service binds to all network interfaces, does not require an API key, and permits wildcard Cross-Origin Resource Sharing. As a result, an attacker who can reach the host can perform unauthenticated GET requests to /api/agents to read instructions and system prompts that may contain sensitive information, or POST to /api/chat to invoke agents. This allows unintended disclosure of internal configuration and could enable further malicious interaction with the system.
Affected Systems
The vulnerability applies to all deployments of MervinPraison’s PraionAI product with a version number prior to 1.7.3.
Risk and Exploitability
The CVSS score of 8.8 classifies this as a high severity vulnerability, meaning it can have a substantial impact on confidentiality, integrity, or availability. The EPSS score of less than 1% indicates that exploit attempts are currently rare, though not impossible. Because it is not listed in the CISA KEV catalog, no widespread public exploit activity is known. Based on the description, it is inferred that the attack vector is network-based; an attacker who can reach the PraionAI service port can exploit the insecure default configuration to read agent instructions and system prompts and to invoke agents without authentication. Thus, without mitigation, the vulnerability poses a significant risk to exposed data and unintended execution of potentially harmful agents.
OpenCVE Enrichment