Junglewise Threat Intelligence

CVE-2026-47393: MervinPraison PraisonAI missing authentication in generated API server

CVE-2026-47393 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: praisonai (PyPI). Vendors: PyPI, MervinPraison.

Executive brief

PraisonAI, a system for managing multi-agent AI teams, contains a security flaw in its code-generation tool. When users deploy an API server using the recommended quickstart commands, the system generates a server that has authentication disabled by default. This allows unauthorized individuals to access the AI agents and chat interfaces over the network, potentially exposing sensitive API keys and allowing them to run arbitrary AI tasks at the owner's expense.

Technical details

A vulnerability exists in the PraisonAI code-generator (`praisonai.deploy.api.generate_api_server_code`) where the `APIConfig` class defaults `auth_enabled` to `False`. When a user executes `praisonai deploy --type api`, the resulting Flask application contains a `check_auth()` function that short-circuits to return `True`, effectively disabling authentication for the `/chat` and `/agents` endpoints. Because the recommended deployment binds to `0.0.0.0`, these endpoints are exposed to the network. An attacker can send JSON payloads to these endpoints to trigger `praisonai.run()`, utilizing the LLM API keys stored in the server's environment. The issue is resolved in version 4.6.40 by requiring explicit authentication configuration.

Affected products

  • MervinPraison PraisonAI <= 4.6.39

Timeline

  • 2026-05-19: patched: Fix merged in security batch 2 hardening PR #1685
  • 2026-07-21: advisory: NVD and GitHub Advisory published

References

Related threats