Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-57140: PraisonAI 1.6‑1.7.2 allows unauthenticated access to agents
CVE-2026-57140 · published 25 days ago
Summary
Versions 1.6.0 through 1.7.2 of PraisonAI expose API endpoints that let anyone on the network view agent details and send commands without proving who they are. This could let a remote user control agents, access their tools, memory, external services, and credentials. Upgrade to version 1.7.2 or later, which adds authentication, to close the gap.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| mervinpraison | praisonai | >= 1.6.0, < 1.7.2 |
Original advisory text
PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the 0.0.0.0 default from src/praisonai-ts/src/os/config.ts and registers GET /api...
PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the 0.0.0.0 default from src/praisonai-ts/src/os/config.ts and registers GET /api/agents and POST /api/chat without authentication middleware. A remote caller who can reach the service can obtain agent names, roles, and instruction prefixes and can invoke a selected agent, potentially reaching its tools, memory, external APIs, credentials, and workflow state. An initial remediation was released in version 1.7.2.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published15 Sep 2026
Updated7 Oct 2026
First seen15 Sep 2026
Track software like this
Free during beta