VYPR
Unrated severityNVD Advisory· Published Jul 11, 2026· Updated Jul 13, 2026

PraisonAI before 1.7.3 Unauthenticated Agent Access via Insecure Defaults

CVE-2026-61426

Description

PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents without authentication.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.