THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-gfq8-hmph-9gjv (high) — PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

[GHSA] GHSA-gfq8-hmph-9gjv (high) — PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

medgithub_advisoriesPublished 2026-08-25

GHSA-gfq8-hmph-9gjv Severity: high CVE: CVE-2026-55533

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

### Summary

The PraisonAI Recipe HTTP server silently allows unauthenticated requests when `auth` is configured as `api-key` or `jwt` but the corresponding secret is missing.

This creates an authenticat

Indicators of compromise

Original source: https://github.com/advisories/GHSA-gfq8-hmph-9gjv