Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55538

Опубликовано: 25 авг. 2026
Источник: nvd
CVSS3: 7.3
EPSS Низкий

Описание

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, praisonai serve agents parses config["api_key"] but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. Missing or incorrect bearer and X-API-Key values still reach agent execution. This issue is fixed in version 4.6.58.

EPSS

Процентиль: 17%
0.00258
Низкий

7.3 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.3
github
22 дня назад

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated

EPSS

Процентиль: 17%
0.00258
Низкий

7.3 High

CVSS3

Дефекты

CWE-306