<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T07:31:43.689426+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-55534</id>
    <title>CVE-2026-55534 — PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution</title>
    <updated>2026-10-10T07:31:43.712391+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> MervinPraison PraisonAI</p>
<p>PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. A network caller can invoke configured agents without credentials even when an API key was supplied. This issue is fixed in version 4.6.58.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-55534"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3887</id>
    <title>PYSEC-2026-3887 — PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution</title>
    <updated>2026-10-10T07:31:43.712461+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: praisonai</p>
<p>### Summary</p>
<p>PraisonAI's `praisonai serve agents` command exposes `--api-key` as the documented
  authentication control for production/external deployments, but the configured key is not
  enforced on the public agent invocation compatibility endpoints.</p>
<p>An operator can start the server with `--api-key` and bind it to `0.0.0.0`, but any network-
  reachable caller can still invoke agents through `POST /agents` or `POST /agents/
  {agent_name}` without `Authorization`, `X-API-Key`, a query token, or any other credential.</p>
<p>Confirmed vulnerable:
  - v4.6.48 / commit `d5f1114aaf1a2e9f121a6e66b929149ca2201f1d`
  - v4.6.34 / commit `e5928449f73f66cc8af1de61621aa974ab255133`</p>
<p>Likely affected range: `&gt;= 4.6.34, &lt;= 4.6.48`.</p>
<p>This is distinct from CVE-2026-44338 / GHSA-6rmh-7xcm-cpxj, which covered the legacy Flask
  `api_server.py` path before 4.6.34. This report concerns the newer FastAPI `serve agents
  --api-key` code path and is confirmed in v4.6.48.</p>
<p>### Details</p>
<p>The CLI accepts and forwards an API key:</p>
<p>- `src/praisonai/praisonai/cli/commands/serve.py:156` defines `praisonai serve agents`
  - `src/praisonai/praisonai/cli/commands/serve.py:162` exposes `--api-key`
  - `src/praisonai/praisonai/cli/commands/serve.py:175-176` forwards the supplied key
  - `src/praisonai/praisonai/cli/features/serve.py:191` handles the `agents` subcommand
  - `src/praisonai/praisonai/cli/features/serve.py:199` parses `api_key` into the config</p>
<p>However, `_create_agents_app()` never…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3887"/>
  </entry>
</feed>
