HighVulnerability
GHSA-6wjp-v33h-5cvq: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure
- Identifiers
- CVE-2026-61426GHSA-6wjp-v33h-5cvq
- Published
- Record updated
Summary
The AgentOS server in the praisonai TypeScript/npm package ships with defaults that bind 0.0.0.0, leave the API key empty, and use wildcard CORS with credentials. Because the auth middleware is only registered when an apiKey is set, the documented quickstart exposes GET /api/agents, which returns agent names, roles and instructions, and POST /api/chat, which invokes agents, to any network peer without authentication. The advisory is rated High and was confirmed at runtime.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- MediumGHSA-hmq2-7hp6-7crh: Banks: User-controlled prompt input can be parsed as privileged chat messagesSimilar attack · GitHub Advisory Database
- HighCVE-2026-101998: Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read…Similar attack · NVD/CVE Database
- MediumEncrypted instructions trick Copilot CLI into spilling developer secretsSimilar attack · CSO Online
- HighCVE-2026-93677: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due…Similar attack · NVD/CVE Database
- HighCVE-2026-101331: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due…Similar attack · NVD/CVE Database