THREAT OPS › Threat News › [GHSA] GHSA-7ww9-85pg-cv4x (high) — PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
[GHSA] GHSA-7ww9-85pg-cv4x (high) — PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
GHSA-7ww9-85pg-cv4x Severity: high CVE: CVE-2026-55534
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
### Summary
PraisonAI's `praisonai serve agents` command exposes `--api-key` as the documented authentication control for production/external deployments, but the configured key is not enforced on the public agent invocation compatibility endp
Indicators of compromise
- d5f1114aaf1a2e9f121a6e66b929149ca2201f1dsha1
- e5928449f73f66cc8af1de61621aa974ab255133sha1
- CVE-2026-55534cve
- CVE-2026-44338cve
Original source: https://github.com/advisories/GHSA-7ww9-85pg-cv4x