THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7g3p-92qq-8wvh (high) — praisonaiagents: AgentServer declares auth_token but never enforces it on any route

[GHSA] GHSA-7g3p-92qq-8wvh (high) — praisonaiagents: AgentServer declares auth_token but never enforces it on any route

highgithub_advisoriesPublished 2026-08-25

GHSA-7g3p-92qq-8wvh Severity: high CVE: CVE-2026-55528

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

**Researcher:** Kai Aizen — SnailSploit (@SnailSploit), Adversarial & Offensive Security Research **Target:** https://github.com/MervinPraison/PraisonAI

---

**Package:** `praisonaiagents` on PyPI **Affected version (empirically tested):** 1.6.48 **Component

Indicators of compromise

Original source: https://github.com/advisories/GHSA-7g3p-92qq-8wvh