{"data":{"id":"bd176a59-c088-4846-adbd-8572df6db442","title":"GHSA-6wjp-v33h-5cvq: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure","summary":"The AgentOS server in the praisonai TypeScript/npm package ships with defaults that bind 0.0.0.0, leave the API key empty, and use wildcard CORS with credentials. Because the auth middleware is only registered when an apiKey is set, the documented quickstart exposes GET /api/agents, which returns agent names, roles and instructions, and POST /api/chat, which invokes agents, to any network peer without authentication. The advisory is rated High and was confirmed at runtime.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-6wjp-v33h-5cvq","publishedAt":"2026-10-08T22:01:29.000Z","cveId":"CVE-2026-61426","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["data_extraction","jailbreak"],"issueType":"vulnerability","affectedPackages":["praisonai@< 1.7.3 (fixed: 1.7.3)"],"affectedPackageNames":["praisonai"],"affectedVendors":[],"affectedVendorsRaw":["PraisonAI","AgentOS"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00478,"epssCheckedAt":"2026-10-10T02:56:51.777Z","kevDateAdded":null,"advisoryAliases":["GHSA-6wjp-v33h-5cvq"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2026-10-08T22:01:29.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}