Security Flaw in PraisonAI Multi-Agent System Affects Unauthorized Access and Job Management
CVE-2026-57131

9.8CRITICAL

Key Information:

Status
Vendor
CVE Published:
14 September 2026

What is CVE-2026-57131?

The PraisonAI multi-agent system prior to version 4.6.58 is susceptible to a security flaw where the API endpoint /api/v1/runs allows unauthenticated network clients to execute various malicious actions. Attackers can submit controlled prompts and configurations, list and retrieve jobs, stream outputs, and even cancel or remove other jobs. This vulnerability creates significant risks by exposing service credentials and enabling unauthorized execution of connected tools, thereby compromising the overall integrity of the system.

Affected Version(s)

PraisonAI < 4.6.48

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.