Vulnerability in PraisonAI Affecting User Authentication
CVE-2026-57147
9.8CRITICAL
What is CVE-2026-57147?
PraisonAI, a multi-agent team system, experienced a significant security flaw prior to version 0.1.6. The Auth Service's JWT_SECRET was insecurely assigned a default value of 'dev-secret-change-me' when the PLATFORM_JWT_SECRET was not set. This misconfiguration allows remote, unauthenticated attackers to forge HS256 tokens, impersonating users by creating arbitrary 'sub' and 'email' claims. As a result, protected API routes incorrectly authorize these forged identities. This vulnerability was addressed in PraisonAI version 0.1.6.
Affected Version(s)
PraisonAI < 4.6.51
praisonai-platform < 0.1.6
