PT-2026-59541 · Pypi · Praisonai

Published

2026-07-13

·

Updated

2026-07-13

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Summary

PraisonAI ships a legacy Flask API server with authentication disabled by default. When that server is used, any caller that can reach it can access /agents and trigger the configured agents.yaml workflow through /chat without providing a token.

Details

The vulnerable server is the shipped src/praisonai/api server.py entrypoint.
The deploy subsystem keeps the same insecure authentication default:
  • APIConfig defaults auth enabled to False in [src/praisonai/praisonai/deploy/models.py](/Users/shmulc/Stuff/tmp/first-cve/scans/variant-hunt/PraisonAI/src/praisonai/praisonai/deploy/models.py:23).
  • The generated sample API deployment YAML recommends host: 0.0.0.0 together with auth enabled: false in [src/praisonai/praisonai/deploy/schema.py](/Users/shmulc/Stuff/tmp/first-cve/scans/variant-hunt/PraisonAI/src/praisonai/praisonai/deploy/schema.py:108).
For scope clarity: the newer serve agents command is safer by default, because it binds to 127.0.0.1 and supports --api-key in [src/praisonai/praisonai/cli/commands/serve.py](/Users/shmulc/Stuff/tmp/first-cve/scans/variant-hunt/PraisonAI/src/praisonai/praisonai/cli/commands/serve.py:155). This report is about the shipped legacy API server and the generated/sample API deployment path above.
Version scope:
  • v2.5.6 already ships the same src/praisonai/api server.py implementation.
  • The current PyPI release on May 1, 2026 is 4.6.33, and it still ships the same unauthenticated server logic.

PoC

The following route-level reproduction was verified locally and proves that the shipped api server.py exposes /agents and /chat without authentication.
  1. From the repository root, create a throwaway environment with the server's direct Flask dependencies:
bash
python3 -m venv /tmp/praisonai-ghsa-venv
/tmp/praisonai-ghsa-venv/bin/pip install flask flask-cors
  1. Execute the shipped src/praisonai/api server.py under a minimal stub for praisonai.PraisonAI so only the server auth logic is exercised:
bash
/tmp/praisonai-ghsa-venv/bin/python - <<'PY'
import importlib.util
import pathlib
import sys
import types

stub = types.ModuleType("praisonai")

class DummyPraisonAI:
  def  init (self, agent file="agents.yaml"):
    self.agent file = agent file
  def run(self):
    return {"ran": True, "agent file": self.agent file}

stub.PraisonAI = DummyPraisonAI
sys.modules["praisonai"] = stub

path = pathlib.Path("src/praisonai/api server.py").resolve()
spec = importlib.util.spec from file location("api server local", path)
mod = importlib.util.module from spec(spec)
spec.loader.exec module(mod)

client = mod.app.test client()
print(client.get("/agents").status code, client.get("/agents").get data(as text=True))
print(client.post("/chat", json={"message": "hello"}).status code, client.post("/chat", json={"message": "hello"}).get data(as text=True))
PY
  1. Observed result:
text
200 {"agent file":"agents.yaml","agents":["default"]}
200 {"response":{"agent file":"agents.yaml","ran":true},"status":"success"}
Both endpoints succeed without any Authorization header.

Impact

Any reachable caller can invoke the legacy API server's protected functionality without a token.
At minimum, this allows:
  • unauthenticated enumeration of the configured agent file through /agents
  • unauthenticated triggering of the locally configured agents.yaml workflow through /chat
  • repeated consumption of model/API quota and any other side effects performed by that workflow
  • exposure of whatever result PraisonAI.run() returns to the unauthenticated caller
This is not the same as arbitrary prompt injection by itself, because the current /chat handler ignores the submitted message value and simply runs the configured workflow. The impact therefore depends on what the operator's agents.yaml is allowed to do, but the authentication bypass is unconditional in the shipped legacy server.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2026-2904

Affected Products

Praisonai