THREAT OPS › Threat News › [GHSA] GHSA-7g3p-92qq-8wvh (high) — praisonaiagents: AgentServer declares auth_token but never enforces it on any route
[GHSA] GHSA-7g3p-92qq-8wvh (high) — praisonaiagents: AgentServer declares auth_token but never enforces it on any route
GHSA-7g3p-92qq-8wvh Severity: high CVE: CVE-2026-55528
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
**Researcher:** Kai Aizen — SnailSploit (@SnailSploit), Adversarial & Offensive Security Research **Target:** https://github.com/MervinPraison/PraisonAI
---
**Package:** `praisonaiagents` on PyPI **Affected version (empirically tested):** 1.6.48 **Component
Indicators of compromise
- aac9497d515b5cb928070267b860b11ef38b537605e64659feef895b524ca7e4sha256
- CVE-2026-55528cve
- http://127.0.0.1:{PORT}{path}url
- http://127.0.0.1:{PORT}/eventsurl
Original source: https://github.com/advisories/GHSA-7g3p-92qq-8wvh