Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
CVE-2026-61426: PraisonAI before 1.7.3 allows unauthenticated access to chat data
CVE-2026-61426
Summary
PraisonAI, a chat software, has a default setting that lets anyone access its data without a password. This means that hackers can read and manipulate chat conversations and system prompts. To fix this, update PraisonAI to version 1.7.3 or higher.
Original title
PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to r...
Original description
PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents without authentication.
nvd CVSS3.1
8.6
nvd CVSS4.0
8.8
Vulnerability type
CWE-200
Information Exposure
Published: 11 Jul 2026 · Updated: 20 Jul 2026 · First seen: 11 Jul 2026