{"data":{"id":"06f50476-141e-45e8-a36d-4903d921d65b","title":"GHSA-7ww9-85pg-cv4x: PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution","summary":"PraisonAI's `praisonai serve agents` command accepts an `--api-key` parameter to secure agent access, but the key is not actually enforced on the public endpoints (`POST /agents` and `POST /agents/{agent_name}`). This means anyone on the network can run agents without providing any credentials, even if the operator started the server with an API key. The vulnerability affects versions 4.6.34 through 4.6.48.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-7ww9-85pg-cv4x","publishedAt":"2026-08-25T14:42:25.000Z","cveId":"CVE-2026-55534","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["PraisonAI@>= 4.6.34, < 4.6.58 (fixed: 4.6.58)"],"affectedVendors":[],"affectedVendorsRaw":["PraisonAI"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-08-25T14:42:25.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}