Security Flaw in PraisonAI Multi-Agent System Affects Unauthorized Access and Job Management
CVE-2026-57131
9.8CRITICAL
What is CVE-2026-57131?
The PraisonAI multi-agent system prior to version 4.6.58 is susceptible to a security flaw where the API endpoint /api/v1/runs allows unauthenticated network clients to execute various malicious actions. Attackers can submit controlled prompts and configurations, list and retrieve jobs, stream outputs, and even cancel or remove other jobs. This vulnerability creates significant risks by exposing service credentials and enabling unauthorized execution of connected tools, thereby compromising the overall integrity of the system.
Affected Version(s)
PraisonAI < 4.6.48
