Cross-Origin Agent Execution Vulnerability in PraisonAI by Mervin Praison
CVE-2026-56076
8.6HIGH
What is CVE-2026-56076?
PraisonAI versions prior to 1.5.128 are susceptible to a cross-origin agent execution vulnerability affecting the AGUI endpoint. This security flaw allows remote attackers to exploit the lack of authentication and the hardcoded Access-Control-Allow-Origin: * headers, effectively bypassing CORS preflight checks. As a consequence, attackers can initiate simple requests, triggering arbitrary agent execution and exfiltrating sensitive information, which may include execution results and critical environment data.
Affected Version(s)
PraisonAI 0 < 1.5.128
PraisonAI 1.5.128
