CVE-2026-61426
MervinPraison PraisonAI
PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents without authentication.
- CVSS
- 8.8
- EPSS
- 0.32% 24.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.11