API Authentication Flaw in PraisonAI Multi-Agent Teams System
CVE-2026-55538
7.3HIGH
What is CVE-2026-55538?
PraisonAI, a multi-agent teams system, has a critical flaw in its API authentication process. Prior to version 4.6.51, the application improperly handled configuration settings for the 'api_key', allowing unauthorized agents to execute actions without proper authentication. Specifically, the methods for creating agents did not require valid bearer tokens or X-API-Key values for POST requests to /agents or /agents/{agent_name}. This oversight could lead to exposure and exploitation of sensitive functionalities by malicious users. The issue has been resolved in version 4.6.58, where enhanced authentication measures are implemented to prevent such unauthorized access.
Affected Version(s)
PraisonAI < 4.6.58
