Vulnerability in PraisonAI Affecting User Authentication
CVE-2026-57147

9.8CRITICAL

Key Information:

Vendor
CVE Published:
15 September 2026

What is CVE-2026-57147?

PraisonAI, a multi-agent team system, experienced a significant security flaw prior to version 0.1.6. The Auth Service's JWT_SECRET was insecurely assigned a default value of 'dev-secret-change-me' when the PLATFORM_JWT_SECRET was not set. This misconfiguration allows remote, unauthenticated attackers to forge HS256 tokens, impersonating users by creating arbitrary 'sub' and 'email' claims. As a result, protected API routes incorrectly authorize these forged identities. This vulnerability was addressed in PraisonAI version 0.1.6.

Affected Version(s)

PraisonAI < 4.6.51

praisonai-platform < 0.1.6

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.