Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-7g3p-92qq-8wvh | praisonaiagents: AgentServer declares auth_token but never enforces it on any route |
Tue, 25 Aug 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, AgentServer exposes ServerConfig.auth_token but AgentServer._create_app does not check it on any route. A remote caller can subscribe, publish, and perform other actions without a valid bearer token or X-Auth-Token even when authentication is configured. This issue is fixed in version 1.6.58. | |
| Title | praisonaiagents: AgentServer declares auth_token but never enforces it on any route (CWE-862) | |
| Weaknesses | CWE-306 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-25T14:32:05.929Z
Reserved: 2026-06-16T23:01:04.073Z
Link: CVE-2026-55528
No data.
Status : Received
Published: 2026-08-25T15:16:33.590
Modified: 2026-08-25T15:16:33.590
Link: CVE-2026-55528
No data.
OpenCVE Enrichment
No data.
Github GHSA