PT-2026-108658 · Pypi · Praisonai

Published

2026-07-15

·

Updated

2026-07-15

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-2gpf-2492-q9jh. This link is maintained to preserve external references.

Original Description

PraisonAI before 4.6.78 contains an authentication bypass in the Call API agent invocation endpoints (src/praisonai/praisonai/api/agent invoke.py) when PRAISONAI CALL AUTH=disabled is configured. The safeguard intended to restrict the disabled-auth opt-out to localhost binding derives the bind host from request.url.hostname, which is taken from the client-controlled HTTP Host header. A remote, unauthenticated attacker who can reach the service over the network can send a spoofed 'Host: 127.0.0.1' header to bypass the localhost-only restriction and list (GET /api/v1/agents) and invoke (POST /api/v1/agents/{agent id}/invoke) registered agents without authentication.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-GP65-M7Q3-4VJW

Affected Products

Praisonai