GHSA-7ww9-85pg-cv4x: PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
Summary
PraisonAI's `praisonai serve agents` command accepts an `--api-key` parameter to secure agent access, but the key is not actually enforced on the public endpoints (`POST /agents` and `POST /agents/{agent_name}`). This means anyone on the network can run agents without providing any credentials, even if the operator started the server with an API key. The vulnerability affects versions 4.6.34 through 4.6.48.
Vulnerability Details
EPSS: 0.0%
Yes
August 25, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-7ww9-85pg-cv4x
First tracked: August 25, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 92%