Executive brief
PraisonAI is an AI agent framework used to automate tasks and interact with local systems. A security flaw in its web interface allows a malicious website to silently execute commands on a user's local machine if they have the PraisonAI server running. This could lead to the theft of sensitive files, exposure of environment variables, or unauthorized access to the user's local network and data.
Technical details
The vulnerability exists in the `POST /agui` endpoint of the PraisonAI AGUI component. It stems from three combined issues: a lack of authentication on the endpoint, hardcoded `Access-Control-Allow-Origin: *` headers, and reliance on Starlette/FastAPI's JSON parsing which does not strictly enforce the `application/json` Content-Type. An attacker can craft a malicious website that sends a 'simple request' (using `text/plain`) to a victim's locally running AGUI server. Because the request is classified as a simple request, it bypasses CORS preflight checks; the server then executes the agent's instructions (which may include tool use like filesystem access) and returns the results. Due to the wildcard CORS header, the attacker's JavaScript can read the response and exfiltrate sensitive data. The issue is patched in version 1.5.128.
Affected products
- PraisonAI praisonaiagents < 1.5.128
Timeline
- 2026-04-09: advisory: Vendor security advisory published on GitHub
- 2026-06-18: disclosed: CVE published to NVD