THREAT OPS › Threat News › [GHSA] GHSA-r7v3-x45f-g7hp (high) — PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
[GHSA] GHSA-r7v3-x45f-g7hp (high) — PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
GHSA-r7v3-x45f-g7hp Severity: high CVE: CVE-2026-55538
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
### Summary `praisonai serve agents` exposes HTTP routes that invoke registered agents. The CLI advertises `--api-key` with help text "API key for authentication", parses
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-55538cve
- http://TARGET:8765/agents/ownedurl
Original source: https://github.com/advisories/GHSA-r7v3-x45f-g7hp