<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T08:36:57.554533+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-57131</id>
    <title>CVE-2026-57131 — praisonai: Jobs API exposes agent-execution endpoints with no authentication</title>
    <updated>2026-10-04T08:36:57.584548+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> MervinPraison PraisonAI</p>
<p>PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker-controlled prompts and agent configuration, list and read jobs, stream results, and cancel or delete other jobs, exposing service credentials and connected tool capabilities to unauthorized agent execution. This vulnerability is fixed in 4.6.58.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-57131"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fq2m-6wqh-x44g</id>
    <title>GHSA-fq2m-6wqh-x44g — PraisonAI: Jobs API exposes agent-execution endpoints with no authentication</title>
    <updated>2026-10-04T08:36:57.584605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: praisonai</p>
<p># praisonai: Jobs API exposes agent-execution endpoints with no authentication</p>
<p>**Researcher:** Kai Aizen — SnailSploit (@SnailSploit), Adversarial &amp; Offensive Security Research 
**Target:** https://github.com/MervinPraison/PraisonAI</p>
<p>---</p>
<p>**Package:** `praisonai` on PyPI
**Affected version (empirically tested):** 4.6.48
**Components:**
- `praisonai.jobs.server.create_app` — `praisonai/jobs/server.py`
- `praisonai.jobs.router.create_router` — `praisonai/jobs/router.py`
- Routes mounted at `/api/v1/runs/...`
**Weakness:** CWE-306 Missing Authentication for Critical Function · CWE-862 Missing Authorization · CWE-94 Code Injection (via prompt / agent_yaml).</p>
<p>---</p>
<p>## TL;DR</p>
<p>`praisonai` ships a standalone async-jobs HTTP server (`python -m praisonai.jobs.server --host=0.0.0.0 --port=8005`) whose job is to accept job submissions and run agents on the operator's behalf. Every endpoint under `/api/v1/runs` is **unauthenticated**. There is no `auth_token` field, no `Depends(verify_*)`, no middleware that inspects `Authorization` — the CORS middleware *lists* `Authorization` in `allow_headers` (the only signal in the whole module that the developer was aware authentication is a thing), but no route ever reads it.</p>
<p>A network-reachable attacker can:</p>
<p>1. **Execute arbitrary agent code** — `POST /api/v1/runs` accepts `prompt`, `agent_yaml`, `agent_file`, `config`, `framework`. The job is queued and an executor invokes whichever framework (`praisonai` / `crewai` / `autogen`) the attacker…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fq2m-6wqh-x44g"/>
  </entry>
</feed>
