top of page
perceptive_background_267k.jpg

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function mounts /api/v1/runs without authentication. Any reachable c…

Published:

25 August 2026 at 00:00:00

Alert date:

25 August 2026 at 19:07:30

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Emerging Technologies

PraisonAI, a multi-agent teams system, contains a critical vulnerability in its Jobs API where the create_app function mounts the /api/v1/runs endpoint without any authentication. Prior to version 4.6.51, any reachable caller could exploit this to submit jobs, read results, cancel runs, or delete jobs using operator-level credentials. This effectively grants unauthorized users full control over job operations without requiring any credentials. The vulnerability poses significant risk as it allows unauthenticated access to sensitive job management functionality. The fix introduces PRAISONAI_JOBS_API_KEY middleware that enforces authentication via Authorization or X-API-Key headers. The issue has been patched in version 4.6.58 of PraisonAI.

Technical details

Mitigation steps:

Affected products:

PraisonAI

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page