THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2jgc-f764-c5r2 (high) — PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

[GHSA] GHSA-2jgc-f764-c5r2 (high) — PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

highgithub_advisoriesPublished 2026-08-25

GHSA-2jgc-f764-c5r2 Severity: high CVE: CVE-2026-55539

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

### Summary PraisonAI's async **Jobs API** (the FastAPI service in `praisonai/jobs/`) installs its router with no authentication middleware, no router-level dependency, and no per-route aut

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2jgc-f764-c5r2