Authentication Bypass in PraisonAI Multi-Agent Teams System
CVE-2026-55533
8.2HIGH
What is CVE-2026-55533?
PraisonAI, a multi-agent teams system, contains a flaw prior to version 4.6.58 where the create_auth_middleware() function allows unauthenticated requests when api-key authentication is not provided or if JWT authentication is missing the required PRAISONAI_JWT_SECRET. This vulnerability permits an externally connected Recipe server to accept unauthorized POST requests to /v1/recipes/run even when authentication measures are ostensibly in place. It is crucial for users of the affected versions to upgrade to version 4.6.58 to mitigate this issue.
Affected Version(s)
PraisonAI < 4.6.58
