GHSA-g3pq-3vvx-36w6

Suggest an improvement
Source
https://github.com/advisories/GHSA-g3pq-3vvx-36w6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-g3pq-3vvx-36w6/GHSA-g3pq-3vvx-36w6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g3pq-3vvx-36w6
Withdrawn
2026-10-08T22:01:22Z
Published
2026-07-11T15:30:23Z
Modified
2026-10-08T22:15:05Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L CVSS Calculator
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-6wjp-v33h-5cvq. This link is maintained to preserve external references.

Original Description

PraisonAI before 1.7.3 contains an insecure default configuration that binds to all interfaces with no API key requirement and wildcard CORS. Unauthenticated attackers can call GET /api/agents to read agent instructions and system prompts, or POST /api/chat to invoke agents without authentication.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-08T22:01:22Z",
    "nvd_published_at": "2026-07-11T14:16:22Z",
    "severity": "HIGH"
}
References

Affected packages

npm / praisonai

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

last_known_affected_version_range
"< 1.7.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-g3pq-3vvx-36w6/GHSA-g3pq-3vvx-36w6.json"