{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/praisonai--1.7.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mervinpraison:praisonai:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.6,"id":"CVE-2026-61426"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":[],"_cs_products":["PraisonAI (\u003c 1.7.3)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","insecure-configuration","PraisonAI","cve"],"_cs_type":"advisory","_cs_vendors":["MervinPraison"],"content_html":"\u003cp\u003eCVE-2026-61426 details a critical security vulnerability in PraisonAI software versions prior to 1.7.3. The vulnerability stems from an insecure default configuration where the application binds to all network interfaces without requiring API keys for sensitive operations and utilizes a wildcard CORS policy. This flaw permits unauthenticated attackers to make direct HTTP requests to internal API endpoints. Specifically, attackers can issue a GET request to \u003ccode\u003e/api/agents\u003c/code\u003e to retrieve confidential agent instructions and system prompts, effectively exposing proprietary logic and sensitive data. Furthermore, the absence of authentication allows attackers to send POST requests to \u003ccode\u003e/api/chat\u003c/code\u003e, enabling them to invoke agents and interact with the AI functionalities without authorization. This vulnerability has a CVSS v3.1 base score of 8.6 (High), highlighting its significant risk. Organizations utilizing PraisonAI instances, particularly those exposed to the internet, are at risk of unauthorized access, intellectual property theft, and potential misuse of their AI agents.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eDiscovery of Public-Facing PraisonAI Instance\u003c/strong\u003e: An unauthenticated attacker scans for internet-exposed PraisonAI instances, identifying applications running vulnerable versions.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUnauthenticated Information Gathering (GET /api/agents)\u003c/strong\u003e: The attacker sends an unauthenticated HTTP GET request to the \u003ccode\u003e/api/agents\u003c/code\u003e endpoint of the vulnerable PraisonAI application.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eSensitive Information Exposure\u003c/strong\u003e: Due to the insecure default configuration (no API key requirement and wildcard CORS), the PraisonAI instance responds with agent instructions and system prompts, disclosing sensitive internal configuration and AI logic.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUnauthenticated Agent Invocation (POST /api/chat)\u003c/strong\u003e: Leveraging the absence of authentication, the attacker then crafts and sends an unauthenticated HTTP POST request to the \u003ccode\u003e/api/chat\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eUnauthorized Agent Operation\u003c/strong\u003e: The PraisonAI application processes the POST request without validating user credentials, allowing the attacker to invoke and interact with AI agents, potentially leading to unauthorized operations or manipulation of AI services.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-61426 leads to severe consequences, primarily unauthorized access to sensitive information and control over AI functionalities. Attackers can exfiltrate proprietary agent instructions and system prompts, which could contain business logic, trade secrets, or data handling methodologies. This exposure can lead to intellectual property theft or provide attackers with insights to further compromise the system. Additionally, the ability to invoke agents without authentication means an attacker can misuse AI resources, potentially consuming computational resources, generating malicious content, or interacting with other systems the AI agents are authorized to access. While no specific victim counts are provided, any organization running an unpatched PraisonAI instance with public exposure is at high risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ePatch CVE-2026-61426\u003c/strong\u003e: Immediately update all PraisonAI instances to version 1.7.3 or higher to address the insecure default configuration.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeploy Detection Rules\u003c/strong\u003e: Deploy the provided Sigma rules (\u003ccode\u003eDetects CVE-2026-61426 Exploitation - GET /api/agents\u003c/code\u003e and \u003ccode\u003eDetects CVE-2026-61426 Exploitation - POST /api/chat\u003c/code\u003e) to your SIEM to detect exploitation attempts.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReview Network Exposure\u003c/strong\u003e: Configure network firewalls and access controls to restrict direct internet access to PraisonAI instances, particularly on sensitive API endpoints.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eEnable Web Server Logging\u003c/strong\u003e: Ensure comprehensive web server logging is enabled to capture HTTP method, URI stem, and request details for forensic analysis and detection rule activation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T01:58:44Z","date_published":"2026-07-11T14:21:33Z","id":"https://feed.craftedsignal.io/briefs/2026-07-praisonai-insecure-config/","summary":"An insecure default configuration in PraisonAI before version 1.7.3 allows unauthenticated attackers to exploit CVE-2026-61426 by reading sensitive agent instructions and system prompts via the `/api/agents` endpoint and invoking agents without authentication through the `/api/chat` endpoint, leading to unauthorized information disclosure and potential control over AI functionalities.","title":"Insecure Default Configuration in PraisonAI Allows Unauthenticated Access","url":"https://feed.craftedsignal.io/briefs/2026-07-praisonai-insecure-config/"}],"language":"en","title":"CraftedSignal Threat Feed - PraisonAI (\u003c 1.7.3)","version":"https://jsonfeed.org/version/1.1"}