CVE 5.3 MEDIUM

PraisonAI Affected by Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS_CVE-2026-40151

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a GET /api/agents endpoint that returns agent names, roles, and the first 100 characters of agent system instructions to any unauthenticated caller. The AgentOS FastAPI application has no authentication middleware, no API key validation, and defaults to CORS allow_origins=["*"] with host="0.0.0.0", making every deployment network-accessible and queryable from any origin by default. This vulnerability is fixed in 4.5.128.

Basic Information

ID CVE-2026-40151
Source GitHub_M
Published Apr 9, 2026 at 21:29
Modified Apr 10, 2026 at 17:10

Affected Product

Vendor MervinPraison
Product PraisonAI
Version < 4.5.128
Affected Versions MervinPraison PraisonAI < 4.5.128

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.