CVE-2026-57132
published 2026-09-14CVE-2026-57132: PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to…
PriorityP350high8.2CVSS 3.1
AVNACLPRNUINSUCHILAN
EPSS
0.29%
21.7th percentile
PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token accept requests to /api/v1/agents/{id}/invoke without CALL_SERVER_TOKEN authentication. Deployments that use the application's advertised opt-out can expose registered agents and their connected tools or private context to unauthenticated invocation. The vulnerability is fixed in 4.6.62.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mervinpraison | praisonai | < 4.6.62 | 4.6.62 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No advisories linked to this vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/MervinPraison/PraisonAI/commit/2a855c470077c7d2e2479a575f7ef7f548d51c33https://github.com/MervinPraison/PraisonAI/releases/tag/v4.6.62https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-8ccj-p46r-jwqqhttps://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-8ccj-p46r-jwqq
2026-09-14
Published