PraisonAI is a multi-agent teams system. Prior to 4.5.128, the AgentOS deployment platform exposes a GET /api/agents endpoint that returns agent names, roles, and the first 100 characters of agent system instructions to any unauthenticated caller. The AgentOS FastAPI application has no authentication middleware, no API key validation, and defaults to CORS allow_origins=["*"] with host="0.0.0.0", making every deployment network-accessible and queryable from any origin by default. This vulnerability is fixed in 4.5.128.
References
| Link | Resource |
|---|---|
| https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-pm96-6xpr-978x | Exploit Vendor Advisory |
Configurations
History
20 Apr 2026, 18:33
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:* | |
| First Time |
Praison
Praison praisonai |
|
| References | () https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-pm96-6xpr-978x - Exploit, Vendor Advisory |
09 Apr 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-09 22:16
Updated : 2026-04-20 18:33
NVD link : CVE-2026-40151
Mitre link : CVE-2026-40151
CVE.ORG link : CVE-2026-40151
JSON object : View
Products Affected
praison
- praisonai
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
