Authentication Bypass Vulnerability in PraisonAI Affects Multi-Agent Systems
CVE-2026-57132
8.2HIGH
What is CVE-2026-57132?
An authentication bypass vulnerability in PraisonAI allows unauthenticated requests to invoke agents without proper authorization. Specifically, when the PRAISONAI_CALL_AUTH is set to 'disabled', the verify_token function can accept requests to the /api/v1/agents/{id}/invoke endpoint without requiring the CALL_SERVER_TOKEN for authentication. This flaw can expose registered agents and their connected tools or private context to potential unauthorized access. The vulnerability has been addressed in version 4.6.62, which users are urged to upgrade to in order to mitigate the risks associated with this issue.
Affected Version(s)
PraisonAI < 4.6.62
