Authentication Flaw in PraisonAI by Mervin Praison
CVE-2026-55528
8.2HIGH
What is CVE-2026-55528?
PraisonAI, a multi-agent teams system developed by Mervin Praison, has an authentication bypass vulnerability affecting versions before 1.6.58. The issue arises from the ServerConfig.auth_token being exposed without proper validation in the AgentServer._create_app method. This flaw enables a remote attacker to perform actions such as subscribing and publishing without needing a valid bearer token or X-Auth-Token, even in environments where authentication is present. This vulnerability highlights significant security concerns and is resolved in version 1.6.58.
Affected Version(s)
PraisonAI < 4.6.58
praisonaiagents < 1.6.58
