Junglewise Threat Intelligence

CVE-2026-40151: PraisonAI AgentOS unauthenticated information disclosure in /api/agents

CVE-2026-40151 · Severity: medium · CVSS 5.3 · Published 2026-04-10

Technologies: praisonai (PyPI). Vendors: MervinPraison, PyPI.

Executive brief

PraisonAI is a platform for deploying AI agents. A security flaw in its AgentOS component allows anyone on the network to view sensitive configuration details, including agent names, roles, and parts of their internal instructions. This could expose proprietary business logic, internal API locations, or other confidential operational data to unauthorized parties.

Technical details

The AgentOS component in PraisonAI fails to implement authentication middleware or API key validation for its FastAPI-based web server. The `GET /api/agents` endpoint returns agent metadata and the first 100 characters of system instructions to any unauthenticated requester. Furthermore, the application defaults to a wildcard CORS policy (`allow_origins=["*"]`) and binds to all interfaces (`0.0.0.0`), enabling cross-origin exfiltration from a user's browser. While the endpoint truncates instructions, an attacker can chain this with the unauthenticated `/api/chat` endpoint to extract full system prompts via prompt injection. This issue was addressed in version 4.5.128.

Affected products

  • MervinPraison PraisonAI < 4.5.128

Timeline

  • 2026-04-09: disclosed
  • 2026-04-10: advisory
  • 2026-04-10: patched: Fixed in version 4.5.128

References

Related threats