<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 16:42:37 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-335954</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-335954</link>
      <description>EUVD-2026-335954</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-335954</guid>
    </item>
    <item>
      <title>fkie_cve-2026-61426</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-61426</link>
      <description>&lt;p&gt;PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents without authentication.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents without authentication.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-61426</guid>
    </item>
    <item>
      <title>GHSA-6wjp-v33h-5cvq — PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6wjp-v33h-5cvq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: praisonai&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The AgentOS server in the `praisonai` TypeScript/npm package ships an insecure default: it binds `0.0.0.0`, sets no API key, and uses CORS `*` with credentials. The API-key middleware is only registered when an API key is configured, so the documented quickstart (`new AgentOS({agents:[...]}).serve({port})`) exposes, **unauthenticated**, `GET /api/agents` (which leaks agent names/roles/instructions, i.e. system prompts) and `POST /api/chat` (which invokes agents). Any network peer can read agent system prompts and drive the agent. Runtime-confirmed; severity High.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Affected component
- Package: `praisonai` (npm / TypeScript). Files `src/praisonai-ts/src/os/config.ts` and `src/praisonai-ts/src/os/agentos.ts` (`AgentOS`).&lt;/p&gt;
&lt;p&gt;### Vulnerable code / root cause&lt;/p&gt;
&lt;p&gt;Path:
`src/praisonai-ts/src/os/config.ts`&lt;/p&gt;
&lt;p&gt;Class/const:
`DEFAULT_AGENTOS_CONFIG` / `mergeConfig`&lt;/p&gt;
&lt;p&gt;Snippet:
```ts
export const DEFAULT_AGENTOS_CONFIG = {
  host: &amp;#39;0.0.0.0&amp;#39;,
  corsOrigins: [&amp;#39;*&amp;#39;],
  apiKey: &amp;#39;&amp;#39;,
  // ...
};
// mergeConfig: apiKey = userConfig?.apiKey ?? process.env.PRAISONAI_AGENTOS_API_KEY ?? &amp;#39;&amp;#39;;
```
Issue: defaults bind all interfaces, with an empty API key and wildcard CORS. `apiKey` stays empty unless the developer explicitly sets it.&lt;/p&gt;
&lt;p&gt;Path:
`src/praisonai-ts/src/os/agentos.ts`&lt;/p&gt;
&lt;p&gt;Function:
`serve` / `_registerRoutes` (Express app)&lt;/p&gt;
&lt;p&gt;Snippet:
```ts
if (this.config.apiKey) {              // auth middleware ONLY added when apiKey is set
  app.use((req,res,next) =&amp;gt; { /* 401 unless Bearer…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: praisonai&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The AgentOS server in the `praisonai` TypeScript/npm package ships an insecure default: it binds `0.0.0.0`, sets no API key, and uses CORS `*` with credentials. The API-key middleware is only registered when an API key is configured, so the documented quickstart (`new AgentOS({agents:[...]}).serve({port})`) exposes, **unauthenticated**, `GET /api/agents` (which leaks agent names/roles/instructions, i.e. system prompts) and `POST /api/chat` (which invokes agents). Any network peer can read agent system prompts and drive the agent. Runtime-confirmed; severity High.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Affected component
- Package: `praisonai` (npm / TypeScript). Files `src/praisonai-ts/src/os/config.ts` and `src/praisonai-ts/src/os/agentos.ts` (`AgentOS`).&lt;/p&gt;
&lt;p&gt;### Vulnerable code / root cause&lt;/p&gt;
&lt;p&gt;Path:
`src/praisonai-ts/src/os/config.ts`&lt;/p&gt;
&lt;p&gt;Class/const:
`DEFAULT_AGENTOS_CONFIG` / `mergeConfig`&lt;/p&gt;
&lt;p&gt;Snippet:
```ts
export const DEFAULT_AGENTOS_CONFIG = {
  host: &amp;#39;0.0.0.0&amp;#39;,
  corsOrigins: [&amp;#39;*&amp;#39;],
  apiKey: &amp;#39;&amp;#39;,
  // ...
};
// mergeConfig: apiKey = userConfig?.apiKey ?? process.env.PRAISONAI_AGENTOS_API_KEY ?? &amp;#39;&amp;#39;;
```
Issue: defaults bind all interfaces, with an empty API key and wildcard CORS. `apiKey` stays empty unless the developer explicitly sets it.&lt;/p&gt;
&lt;p&gt;Path:
`src/praisonai-ts/src/os/agentos.ts`&lt;/p&gt;
&lt;p&gt;Function:
`serve` / `_registerRoutes` (Express app)&lt;/p&gt;
&lt;p&gt;Snippet:
```ts
if (this.config.apiKey) {              // auth middleware ONLY added when apiKey is set
  app.use((req,res,next) =&amp;gt; { /* 401 unless Bearer…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6wjp-v33h-5cvq</guid>
    </item>
  </channel>
</rss>
