CVE-2026-55541
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, praisonai serve agents and praisonai serve unified parse --api-key but _create_agents_app() and _create_unified_app() do not install a credential check. Unauthenticated callers can reach POST /agents and POST /api/v1/agents/{id}/invoke. This issue is fixed in version 4.6.58.
| CWE | CWE-862 |
| Vendor | mervinpraison |
| Product | praisonai |
| Published | Aug 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for mervinpraison praisonai
Be the first to know when new unknown vulnerabilities affecting mervinpraison praisonai are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
MervinPraison / PraisonAI
< 4.6.58