{"id":"GHSA-6wjp-v33h-5cvq","summary":"PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure","details":"## Summary\n\nThe AgentOS server in the `praisonai` TypeScript/npm package ships an insecure default: it binds `0.0.0.0`, sets no API key, and uses CORS `*` with credentials. The API-key middleware is only registered when an API key is configured, so the documented quickstart (`new AgentOS({agents:[...]}).serve({port})`) exposes, **unauthenticated**, `GET /api/agents` (which leaks agent names/roles/instructions, i.e. system prompts) and `POST /api/chat` (which invokes agents). Any network peer can read agent system prompts and drive the agent. Runtime-confirmed; severity High.\n\n## Details\n\n### Affected component\n- Package: `praisonai` (npm / TypeScript). Files `src/praisonai-ts/src/os/config.ts` and `src/praisonai-ts/src/os/agentos.ts` (`AgentOS`).\n\n### Vulnerable code / root cause\n\nPath:\n`src/praisonai-ts/src/os/config.ts`\n\nClass/const:\n`DEFAULT_AGENTOS_CONFIG` / `mergeConfig`\n\nSnippet:\n```ts\nexport const DEFAULT_AGENTOS_CONFIG = {\n  host: '0.0.0.0',\n  corsOrigins: ['*'],\n  apiKey: '',\n  // ...\n};\n// mergeConfig: apiKey = userConfig?.apiKey ?? process.env.PRAISONAI_AGENTOS_API_KEY ?? '';\n```\nIssue: defaults bind all interfaces, with an empty API key and wildcard CORS. `apiKey` stays empty unless the developer explicitly sets it.\n\nPath:\n`src/praisonai-ts/src/os/agentos.ts`\n\nFunction:\n`serve` / `_registerRoutes` (Express app)\n\nSnippet:\n```ts\nif (this.config.apiKey) {              // auth middleware ONLY added when apiKey is set\n  app.use((req,res,next) =\u003e { /* 401 unless Bearer/x-auth-token matches */ });\n}\n// routes:\napp.get(`${apiPrefix}/agents`, ...)    // returns name/role/instructions\napp.post(`${apiPrefix}/chat`,  ...)    // calls agent.chat(message)\n```\nIssue: the only auth gate is conditional on a non-empty `apiKey`. With the default empty key, no auth middleware is registered, and `GET /api/agents` (system-prompt disclosure) and `POST /api/chat` (agent invocation) are served to any network client. CORS sets `Access-Control-Allow-Credentials: true` with a wildcard origin.\n\n### Attack flow\n1. Developer deploys AgentOS via the quickstart without setting `apiKey`/`PRAISONAI_AGENTOS_API_KEY`.\n2. Any network peer calls `GET /api/agents` → receives agent instructions/system prompts.\n3. Any network peer calls `POST /api/chat` → invokes the agent.\n\n### Why existing protection is bypassed\nThere is no protection in the default config — the auth gate is skipped when `apiKey` is empty (the default), and the server binds all interfaces.\n\n### Security boundary\nUnauthenticated network access to agent metadata + invocation. This is the CVE-2026-44338 anti-pattern recurring in the TS package, and worse (0.0.0.0 is the default).\n\n## Proof of Concept\n\n### Environment\nReal AgentOS from `src/praisonai-ts` run via ts-node in a node container with default config (stub agent, no LLM needed). `127.0.0.1:18000`. Runnable assets: `PraisonAI-Runtime-Repro\\runtime-files\\` (`docker-compose.agentos.yml`).\n\n### Steps to reproduce\n1. `PRAI-01-01-AgentOS-Agents-NoAuth`: `GET /api/agents` (no Authorization) → `127.0.0.1:18000`.\n2. `PRAI-01-02-AgentOS-Chat-NoAuth`: `POST /api/chat {\"message\":\"hello from attacker\"}` (no Authorization).\n\n### Expected result\nNon-loopback exposure should require authentication; agent instructions should not be disclosed unauthenticated.\n\n### Actual result\n- `GET /api/agents` → `200`, leaks `\"instructions\":\"SYSTEM PROMPT SECRET ... PRAISONAI_INTERNAL_SECRET_CANARY_7f3a91\"`; response header `Access-Control-Allow-Credentials: true`.\n- `POST /api/chat` → `200`, agent invoked (`\"response\":\"...PRAISONAI_AGENTOS_CANARY_7f3a91...\"`).\n\n### Screenshots\n\n**Unauthenticated `/api/agents` leaks agent instructions**\n\nA GET request to `/api/agents` succeeds without an `Authorization` header. The response exposes agent metadata and instructions, including the canary system-prompt value.\n\n\u003cimg width=\"1535\" height=\"829\" alt=\"01-AgentOS-Agents-NoAuth\" src=\"https://github.com/user-attachments/assets/705087e1-8017-46f6-9a91-edb8312e2f26\" /\u003e\n\n**Unauthenticated `/api/chat` invokes the agent**\n\nA POST request to `/api/chat` succeeds without an `Authorization` header. The response confirms that the attacker-controlled message was processed by the configured agent.\n\n\u003cimg width=\"1537\" height=\"833\" alt=\"02-AgentOS-Chat-NoAuth\" src=\"https://github.com/user-attachments/assets/5cdf8f56-b8d8-498b-87bd-44834f39998c\" /\u003e\n\n### Reproduction assets\n\nThe attached archive contains the local Docker runtime used to reproduce the issue with controlled canary values only. It does not contain real secrets, third-party API keys, or production credentials.\n\n[PraisonAI-Runtime-Repro.zip](https://github.com/user-attachments/files/29143421/PraisonAI-Runtime-Repro.zip)\n\n## Impact\nUnauthenticated disclosure of agent configuration/system prompts; unauthenticated agent invocation; LLM cost abuse; possible tool abuse depending on the configured agent's tools; permissive CORS-with-credentials.\n\n## Suggested remediation\n- Default `host` to `127.0.0.1`; require `apiKey` (fail closed) when binding non-loopback.\n- Do not default `corsOrigins` to `['*']`, especially with `Access-Control-Allow-Credentials: true`.\n- Do not return full `instructions` on an unauthenticated endpoint.","aliases":["CVE-2026-61426"],"modified":"2026-10-08T22:15:05.642584615Z","published":"2026-10-08T22:01:29Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-200","CWE-284","CWE-306"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-10-08T22:01:29Z"},"references":[{"type":"WEB","url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6wjp-v33h-5cvq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61426"},{"type":"PACKAGE","url":"https://github.com/MervinPraison/PraisonAI"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/praisonai-before-unauthenticated-agent-access-via-insecure-defaults"}],"affected":[{"package":{"name":"praisonai","ecosystem":"npm","purl":"pkg:npm/praisonai"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.7.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6wjp-v33h-5cvq/GHSA-6wjp-v33h-5cvq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L"}]}