Executive brief
PraisonAI Platform, a system for managing multi-agent AI teams, contains a security flaw where it uses a publicly known, hardcoded password to secure user login tokens by default. Because this "secret" key is available in the public source code, an attacker can create their own fake login credentials. This allows them to bypass security entirely and log in as any user, including administrators, gaining full access to sensitive data and AI workspaces.
Technical details
The PraisonAI Platform's authentication service (auth_service.py) uses a hardcoded literal `_DEFAULT_SECRET = "dev-secret-change-me"` for JWT signing when the `PLATFORM_JWT_SECRET` environment variable is unset. While a safety check exists to prevent the use of this default secret, the check only triggers if `PLATFORM_ENV` is explicitly set to something other than "dev". Since `PLATFORM_ENV` defaults to "dev", the safety check is bypassed in standard deployments. An unauthenticated remote attacker can use the publicly known secret to mint JWTs with arbitrary 'sub' and 'email' claims, granting them full administrative access to the platform. This issue is resolved in version 0.1.4 by hardening the default configuration.
Affected products
- MervinPraison PraisonAI Platform < 0.1.4
Timeline
- 2026-05-19: patched: Fix merged in commit ef79b7a
- 2026-07-21: disclosed: CVE-2026-47410 published