Junglewise Threat Intelligence

PraisonAI authentication bypass via PRAISONAI_CALL_AUTH environment variable

Severity: high · CVSS 8.2 · Published 2026-06-18

Vendors: MervinPraison.

Executive brief

PraisonAI, a framework for managing AI agents, contains a configuration flaw that can completely disable security protections. If a specific setting is used—which the software itself suggests in error messages—anyone on the network can trigger AI agents without a password. This could allow unauthorized individuals to run tasks or access data through the AI agents' connected tools.

Technical details

A vulnerability in PraisonAI's authentication logic allows for a complete bypass of the verify_token function. The root cause is an explicit check of the PRAISONAI_CALL_AUTH environment variable; if set to 'disabled', the application returns immediately from the authentication middleware without validating credentials. This affects the /api/v1/agents/{id}/invoke endpoint. An unauthenticated remote attacker can exploit this to trigger any registered agent and execute actions via the agent's configured tools. The vulnerability is exacerbated by the application's error messages, which suggest using this insecure configuration. The issue is fixed in version 4.6.61.

Affected products

  • MervinPraison praisonai < 4.6.61

Timeline

  • 2026-06-17: disclosed
  • 2026-06-18: advisory: GHSA-8ccj-p46r-jwqq published
  • 2026-06-18: patched: Version 4.6.61 released

References