Authentication Flaw in PraisonAI by Mervin Praison
CVE-2026-55528

8.2HIGH

Key Information:

Vendor
CVE Published:
25 August 2026

What is CVE-2026-55528?

PraisonAI, a multi-agent teams system developed by Mervin Praison, has an authentication bypass vulnerability affecting versions before 1.6.58. The issue arises from the ServerConfig.auth_token being exposed without proper validation in the AgentServer._create_app method. This flaw enables a remote attacker to perform actions such as subscribing and publishing without needing a valid bearer token or X-Auth-Token, even in environments where authentication is present. This vulnerability highlights significant security concerns and is resolved in version 1.6.58.

Affected Version(s)

PraisonAI < 4.6.58

praisonaiagents < 1.6.58

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.