Junglewise Threat Intelligence

CVE-2026-47396: MervinPraison PraisonAI missing authentication in call server API

CVE-2026-47396 · Severity: critical · CVSS 9.8 · Published 2026-07-21

Technologies: praisonai (PyPI). Vendors: MervinPraison, PyPI.

Executive brief

PraisonAI, a system for managing multi-agent AI teams, contains a security flaw in its call server component. If the server is started without a specific security token configured, it defaults to allowing anyone on the network to access the control panel. An attacker could use this to view sensitive AI instructions, execute AI agents, or shut down active agents, potentially leading to data exposure or service disruption.

Technical details

A missing authentication vulnerability exists in PraisonAI versions prior to 4.6.40. The `verify_token()` helper in `praisonai.api.agent_invoke` fails open if the `CALL_SERVER_TOKEN` environment variable is unset, returning successfully without validating any credentials. Because the call server binds to `0.0.0.0` by default, this flaw exposes sensitive endpoints—including agent invocation, metadata inspection, and unregistration—to any network-reachable client. Attackers can exploit this to leak agent instructions or perform unauthorized actions. The issue is resolved in version 4.6.40 by ensuring authentication is enforced.

Affected products

  • MervinPraison PraisonAI < 4.6.40

Timeline

  • 2026-05-19: patched: Fix committed to repository
  • 2026-07-21: disclosed: CVE-2026-47396 published

References

Related threats