Unrated severityNVD Advisory· Published Jul 11, 2026· Updated Jul 13, 2026
PraisonAI before 1.7.3 Unauthenticated Agent Access via Insecure Defaults
CVE-2026-61426
Description
PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents without authentication.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6wjp-v33h-5cvqmitrevendor-advisory
- www.vulncheck.com/advisories/praisonai-before-unauthenticated-agent-access-via-insecure-defaultsmitrethird-party-advisory
News mentions
0No linked articles in our index yet.