CVE-2026-61426
published 2026-07-11CVE-2026-61426: PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated…
PriorityP263high8.6CVSS 3.1
AVNACLPRNUINSUCHILAL
EPSS
0.48%
38.6th percentile
PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents without authentication.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mervinpraison | praisonai | < 1.7.3 | 1.7.3 |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
nvdv4.08.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
MervinPraison PraisonAI up to 1.7.2 Default Configuration /api/agents information disclosure (EUVD-2026-43176)
vuldb·2026-07-11·CVSS 8.6
CVE-2026-61426 [HIGH] MervinPraison PraisonAI up to 1.7.2 Default Configuration /api/agents information disclosure (EUVD-2026-43176)
A vulnerability identified as problematic has been detected in MervinPraison PraisonAI up to 1.7.2. The impacted element is an unknown function of the file /api/agents of the component Default Configuration. The manipulation leads to information disclosure.
This vulnerability is listed as CVE-2026-61426. The attack may be initiated remotely. There is no available exploit.
GHSA
PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS.
ghsa_unreviewed·2026-07-11
CVE-2026-61426 [HIGH] CWE-200 PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS.
PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents without authentication.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-11
Published