CVE-2026-47393
published 2026-07-21CVE-2026-47393: PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator…
PriorityP268critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.78%
54.4th percentile
PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) that emits a Flask API server with authentication disabled by default. Users who follow the documented quickstart (`praisonai deploy --type api`) get a server that binds to `0.0.0.0` per the recommended sample YAML, exposes `/chat` and `/agents` endpoints, runs `praisonai.run()` on user-supplied JSON input — LLM orchestration with the API key materials present in the process environment, and does not require any authentication. Versions prior to 4.6.40 still ship the generator with `auth_enabled` defaulting to `False`. The fix shape is opt-in via `APIConfig(auth_enabled=True, auth_token=...)`. Version 4.6.40 fixes the issue.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mervinpraison | praisonai | >= 0 < 4.6.40 | 4.6.40 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
MervinPraison PraisonAI up to 4.6.37 Flask Server missing authentication
vuldb·2026-05-30
CVE-2026-47393 [CRITICAL] MervinPraison PraisonAI up to 4.6.37 Flask Server missing authentication
A vulnerability classified as critical has been found in MervinPraison PraisonAI. Affected by this issue is some unknown functionality of the component Flask Server. Performing a manipulation results in missing authentication.
This vulnerability is identified as CVE-2026-47393. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
GHSA
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
ghsa·2026-05-29·CVSS 7.3
CVE-2026-47393 [HIGH] CWE-1188 PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
### Summary
CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.generate_api_server_code`) that emits a Flask API server with authentication disabled by default. Users who follow the documented quickstart (`praisonai deploy --type api`) get a server that:
- binds to `0.0.0.0` per the recommended sample YAML
- exposes `/chat` and `/agents` endpoints
- runs `praisonai.run()` on user-supplied JSON input — LLM orchestration with the API key materials present in the process environment
- does not require any authentication
The PyPI wheel `praisonai==4.6.33` (current `@latest`) still ships the generator with `auth_enabled` defaulting to `False`. T
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/MervinPraison/PraisonAI/commit/ef79b7a0561796ad9807f0f09538c25cc78d3619https://github.com/MervinPraison/PraisonAI/pull/1685https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-8444-4fhq-fxpqhttps://github.com/advisories/GHSA-6rmh-7xcm-cpxjhttps://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-8444-4fhq-fxpq
2026-07-21
Published