{"data":{"id":"84162046-52b2-42ea-9664-bdf7322931b1","title":"GHSA-2jgc-f764-c5r2: PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete","summary":"PraisonAI's Jobs API (a FastAPI service that runs AI agent jobs) has no authentication checks on any of its endpoints. This means anyone who can reach the server can submit jobs to run against the system's AI credentials, view all jobs and their results, cancel running jobs, and delete completed jobs without providing any token, password, or proof of identity. The vulnerability is separate from a similar bug that was already fixed in an older Flask-based API component, but this FastAPI jobs module was left unpatched.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-2jgc-f764-c5r2","publishedAt":"2026-08-25T15:14:27.000Z","cveId":"CVE-2026-55539","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["PraisonAI@< 4.6.58 (fixed: 4.6.58)"],"affectedVendors":["LangChain"],"affectedVendorsRaw":["PraisonAI"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-08-25T15:14:27.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}