<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T12:35:12.100014+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-335954</id>
    <title>EUVD-2026-335954</title>
    <updated>2026-10-10T12:35:12.168773+00:00</updated>
    <content>EUVD-2026-335954</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-335954"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-61426</id>
    <title>fkie_cve-2026-61426</title>
    <updated>2026-10-10T12:35:12.168827+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents without authentication.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-61426"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6wjp-v33h-5cvq</id>
    <title>GHSA-6wjp-v33h-5cvq — PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction…</title>
    <updated>2026-10-10T12:35:12.168873+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: praisonai</p>
<p>## Summary</p>
<p>The AgentOS server in the `praisonai` TypeScript/npm package ships an insecure default: it binds `0.0.0.0`, sets no API key, and uses CORS `*` with credentials. The API-key middleware is only registered when an API key is configured, so the documented quickstart (`new AgentOS({agents:[...]}).serve({port})`) exposes, **unauthenticated**, `GET /api/agents` (which leaks agent names/roles/instructions, i.e. system prompts) and `POST /api/chat` (which invokes agents). Any network peer can read agent system prompts and drive the agent. Runtime-confirmed; severity High.</p>
<p>## Details</p>
<p>### Affected component
- Package: `praisonai` (npm / TypeScript). Files `src/praisonai-ts/src/os/config.ts` and `src/praisonai-ts/src/os/agentos.ts` (`AgentOS`).</p>
<p>### Vulnerable code / root cause</p>
<p>Path:
`src/praisonai-ts/src/os/config.ts`</p>
<p>Class/const:
`DEFAULT_AGENTOS_CONFIG` / `mergeConfig`</p>
<p>Snippet:
```ts
export const DEFAULT_AGENTOS_CONFIG = {
  host: '0.0.0.0',
  corsOrigins: ['*'],
  apiKey: '',
  // ...
};
// mergeConfig: apiKey = userConfig?.apiKey ?? process.env.PRAISONAI_AGENTOS_API_KEY ?? '';
```
Issue: defaults bind all interfaces, with an empty API key and wildcard CORS. `apiKey` stays empty unless the developer explicitly sets it.</p>
<p>Path:
`src/praisonai-ts/src/os/agentos.ts`</p>
<p>Function:
`serve` / `_registerRoutes` (Express app)</p>
<p>Snippet:
```ts
if (this.config.apiKey) {              // auth middleware ONLY added when apiKey is set
  app.use((req,res,next) =&gt; { /* 401 unless Bearer…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6wjp-v33h-5cvq"/>
  </entry>
</feed>
