PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents without authentication.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-11 14:16
Updated : 2026-07-13 18:05
NVD link : CVE-2026-61426
Mitre link : CVE-2026-61426
CVE.ORG link : CVE-2026-61426
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
