High · CVSS 7.3 May 8, 2026 · MervinPraison / GitHub Security Advisory

PraisonAI Authentication Bypass

Unauthenticated Agent Workflow Execution via Legacy API Server

Affected versions 2.5.6 through 4.6.34 shipped a legacy Flask API server with authentication hard-coded off. Unauthenticated attackers on a reachable network could enumerate all configured agent metadata and freely invoke workflows — no token, no credentials, no session. The fix is available in 4.6.35; operators running exposed deployments should treat this as an active threat.

1 CVE
7.3 CVSS Score
Auth Bypass
Patched Status

Vulnerability Details

CVE-2026-44338 High · CVSS 7.3 Auth Bypass

PraisonAI Legacy API Server — Disabled Authentication

The legacy Flask API server in src/praisonai/api_server.py hard-codes AUTH_ENABLED = False and AUTH_TOKEN = None. The two affected routes — GET /agents and POST /chat — perform no credential check, allowing any client on the network to enumerate agent configurations and execute arbitrary workflows. Deployment templates compounded the risk by recommending 0.0.0.0 binding with authentication off.

CWE mappings: CWE-306 (Missing Authentication for Critical Function) · CWE-668 (Exposure of Resource to Wrong Sphere) · CWE-1188 (Insecure Default Initialization)
Affected versions: 2.5.6 – 4.6.34  |  Fixed in: 4.6.35

Root Cause

Hard-coded constants in the legacy API server set authentication to disabled by default. The variable names suggest authentication was intentionally bypassed during development and the code was never secured before shipping.

Exposure Surface

Deployment guides recommended binding to all interfaces (0.0.0.0), meaning any host reachable on the network — including internet-facing instances — could reach the unauthenticated endpoints.

Affected Endpoints

GET /agents exposes the full list of configured agent names and metadata. POST /chat accepts a message payload and triggers the configured workflow without any identity check.

Business Impact

Unauthorized workflow execution can drain LLM API quota, exfiltrate data processed by agents, plant adversarial inputs into downstream pipelines, or cause repeated invocations that exhaust rate limits and incur cost.

Attack Chain

1

Reconnaissance

Attacker identifies a PraisonAI legacy API server reachable on the network — via port scan, exposed service banner, or knowledge of deployment conventions. The default port and binding make this straightforward on improperly segmented networks.

No credentials required. The server is reachable by design.

2

Agent Enumeration

A single unauthenticated GET /agents request returns all configured agent names and metadata. This reveals the tool set, model configuration, and workflow structure — everything an attacker needs to craft effective exploitation payloads.

Agent names and configurations are disclosed in plaintext with no authentication gate.

3

Workflow Execution

The attacker sends a crafted POST /chat request with a message payload. The server processes this through the configured agent workflow — invoking LLM calls, executing tools, and processing data — without verifying who triggered the request.

Any workflow, including those with file system or external API access, can be triggered.

4

Impact Realization

Repeated invocations exhaust LLM API quota and rate limits, incurring financial cost. Adversarial inputs can poison agent memory or downstream pipelines. Data returned by the agent may reveal sensitive context. The lack of logging in legacy mode means exploitation may go undetected.

Financial, data integrity, and confidentiality impacts are all achievable from a single unauthenticated connection.

Defensive Tutorial

IMMEDIATE · 0–24 HRS

Upgrade to 4.6.35 or later

Immediate

The fix ships in version 4.6.35. Run pip install --upgrade praisonai and verify the installed version. If a controlled upgrade is not immediately possible, block network access to the API server port at the firewall as an interim control.

IMMEDIATE · 0–24 HRS

Inventory running PraisonAI services

Immediate

Scan your infrastructure for PraisonAI instances running the legacy API server. Check for processes listening on the default API port across development, staging, and production environments. Container orchestration logs and service discovery tools can accelerate this.

IMMEDIATE · 0–24 HRS

Block network access to exposed instances

Immediate

Apply firewall rules or security group changes to restrict access to the legacy API server port. Only allow connections from known, trusted IP ranges. Any instance bound to 0.0.0.0 should be treated as potentially compromised until access logs are reviewed.

IMMEDIATE · 0–24 HRS

Review access logs for unauthorized requests

Immediate

Search web server and application logs for hits against /agents and /chat from unexpected source IPs. Correlate timestamps against unusual LLM API cost spikes or agent invocation counts. If unauthorized access is confirmed, escalate to incident response.

IMMEDIATE · 0–24 HRS

Rotate downstream credentials if compromise is suspected

Urgent

Agents that processed external data through the unprotected endpoint may have been manipulated into exfiltrating credentials or API keys. If unauthorized access is confirmed or suspected, rotate all credentials accessible to the affected agent workflows — LLM API keys, database passwords, third-party service tokens.

SHORT-TERM · 1–7 DAYS

Bind development and staging to localhost only

Important

Update all deployment configurations and templates to bind the PraisonAI API server to 127.0.0.1 by default. Remove or override any template that recommends 0.0.0.0 binding. Network exposure should be explicitly opt-in, not the default.

SHORT-TERM · 1–7 DAYS

Require an authenticated reverse proxy for all agent APIs

Important

Route all external or cross-service traffic through a reverse proxy (nginx, Caddy, Traefik) that enforces authentication — API key headers, OAuth tokens, or mutual TLS. The application layer should never be the first and only authentication gate for agent endpoints.

LONG-TERM

Register all agent endpoints in your asset inventory

Important

This vulnerability persisted because agent API servers are often launched informally during development and forgotten. Establish a mandatory registration process for any service exposing an agent endpoint — including development instances. Asset inventory is the prerequisite for patch management and incident response.

References

  • GitHub Security Advisory GHSA-6rmh-7xcm-cpxj — PraisonAI Authentication Bypass
  • CVE Program CVE-2026-44338 — PraisonAI Legacy API Server Unauthenticated Access
  • CWE References CWE-306 · Missing Authentication for Critical Function
    CWE-668 · Exposure of Resource to Wrong Sphere
    CWE-1188 · Insecure Default Initialization of Resource
Advisory analysis by Spectreworks AI. Original research by MervinPraison. All defensive recommendations are based on publicly available disclosure information. Verify patch applicability against your specific deployment before production changes.