Executive brief
The PraisonAI npm package contains a server component that allows users to run AI agents. A security flaw in this component allows anyone on the network to view information about configured AI agents and interact with them without any password or authentication. This could allow an attacker to manipulate AI workflows, access sensitive data the agents are authorized to see, or use the agents to perform unauthorized actions in connected business systems.
Technical details
The TypeScript implementation of AgentOS in the 'praisonai' npm package lacks authentication and authorization middleware. The server defaults to binding on '0.0.0.0', making it reachable over the network. Specifically, the 'GET /api/agents' endpoint leaks agent metadata and instruction snippets, while the 'POST /api/chat' endpoint allows unauthenticated callers to invoke 'agent.chat()'. This enables remote attackers to perform prompt injection or trigger agent-linked tools and APIs. The vulnerability exists because 'AgentOS._createApp()' registers routes immediately after basic middleware without any credential validation. A fix is available in version 1.7.2.
Affected products
- MervinPraison praisonai >= 1.6.0, <= 1.7.1
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory
- 2026-06-18: patched: Version 1.7.2 released