{"id":"PYSEC-2026-3507","summary":"PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation","details":"# AgentOS remains unauthenticated after GHSA-pm96 patched version and allows remote agent invocation\n\n## Summary\n\nPraisonAI's `AgentOS` FastAPI deployment surface remains unauthenticated in\ncurrent main and in releases after the published patched version for\n`GHSA-pm96-6xpr-978x` / `CVE-2026-40151`.\n\nThe public AgentOS advisory is published as an instruction-disclosure issue\nwith affected versions `\u003c 4.5.128` and patched version `4.5.128`. However,\n`v4.5.128`, latest release `v4.6.57`, and current main still register\n`GET /api/agents` and `POST /api/chat` without authentication. The chat route\ndirectly calls `agent.chat(request.message)`. No-auth and wrong-bearer requests\nboth execute the deployed agent.\n\nThis is broader than passive metadata disclosure. In any deployment where\nAgentOS wraps agents with tools, private context, memory, API integrations, or\ncost-bearing model calls, an unauthenticated reachable client can drive those\nagents.\n\n## Affected Product\n\n- Repository: `MervinPraison/PraisonAI`\n- Package: `praisonai`\n- Component: `src/praisonai/praisonai/app/agentos.py`\n- Config component: `src/praisonai-agents/praisonaiagents/app/config.py`\n- Public advisory incomplete-fix reference: `GHSA-pm96-6xpr-978x` /\n  `CVE-2026-40151`\n\nConfirmed affected dynamically:\n\n- `v4.5.126`\n- `v4.5.128` (published patched version for `GHSA-pm96-6xpr-978x`)\n- `v4.6.9`\n- `v4.6.10`\n- `v4.6.56`\n- `v4.6.57`\n- current main `2f9677abb2ea68eab864ee8b6a828fd0141612e1`\n\nStatic source review found the same unauthenticated route pattern and\n`0.0.0.0` default in `v4.2.1`.\n\nSuggested affected range: `\u003e= 4.2.1, \u003c= 4.6.57`.\n\n## Root Cause\n\n`AgentOSConfig` / `AgentAppConfig` defaults the deployment host to all\ninterfaces and has no authentication fields:\n\n```python\nname: str = \"PraisonAI App\"\nhost: str = \"0.0.0.0\"\nport: int = 8000\napi_prefix: str = \"/api\"\n```\n\n`AgentOS._register_routes()` registers public agent metadata and chat routes\nwithout middleware, dependency, API key check, bearer-token check, or startup\nfail-closed guard:\n\n```python\n@app.get(f\"{self.config.api_prefix}/agents\")\nasync def list_agents():\n    return {\"agents\": [...]}\n\n@app.post(f\"{self.config.api_prefix}/chat\", response_model=ChatResponse)\nasync def chat(request: ChatRequest):\n    ...\n    response = agent.chat(request.message)\n```\n\nA wrong `Authorization` header is ignored because the route does not inspect it.\n\nCurrent main also has a root-export bug where `from praisonai import AgentOS`\nraises `ImportError`, but this does not mitigate the issue. The same class\nremains reachable through `from praisonai import AgentApp` and\n`from praisonai.app import AgentOS`.\n\n## Why This Is Not Intended Behavior\n\nPraisonAI's security documentation says API servers were hardened so anonymous\nrequests return `401` and default binding changed from `0.0.0.0` to\n`127.0.0.1` after the prior unauthenticated API server class.\n\nThe API Server Authentication docs say bearer auth is enabled by default,\ndisabling auth is not recommended for production, and `0.0.0.0` should be used\nonly behind an authenticating proxy.\n\nThe local PoV includes a hardened sibling control for the generated deploy API\non current main. It returns:\n\n- no auth: `401`\n- wrong bearer: `401`\n- correct bearer: `200`\n\nAgentOS remains outside that control plane and still accepts no-auth and\nwrong-bearer `/api/chat` requests.\n\n## Local PoV\n\nThe PoV is local-only. It uses FastAPI's in-process test client, a stub agent,\nand a temporary file side effect. It does not start a network listener, call an\nLLM provider, or contact any external service.\n\nCommand:\n\n```bash\nenv PYTHONPATH=\"artifacts/repos/praisonai-current/src/praisonai:artifacts/repos/praisonai-current/src/praisonai-agents\" \\\n  uv run --with fastapi --with httpx --with flask --with flask-cors \\\n    --with pydantic --with typing-extensions --with rich --with python-dotenv \\\n    submission-bundle/praisonai-prai-cand-007-agentos-incomplete-auth-fix/poc/prai_cand_007_agentos_incomplete_auth_fix.py \\\n    --repo artifacts/repos/praisonai-current \\\n    --label current-head\n```\n\nCurrent-head result summary:\n\n```json\n{\n  \"describe\": \"v4.6.57-4-g2f9677ab\",\n  \"head\": \"2f9677abb2ea68eab864ee8b6a828fd0141612e1\",\n  \"agentos_vulnerable\": true,\n  \"entrypoints\": [\n    {\n      \"entrypoint\": \"agentapp_alias\",\n      \"statuses\": [200, 200, 200],\n      \"side_effects\": [\"no-auth-marker\", \"wrong-bearer-marker\"]\n    },\n    {\n      \"entrypoint\": \"direct_agentos\",\n      \"statuses\": [200, 200, 200],\n      \"side_effects\": [\"no-auth-marker\", \"wrong-bearer-marker\"]\n    }\n  ],\n  \"deploy_api_control\": {\n    \"control_passed\": true,\n    \"statuses\": [401, 401, 200]\n  }\n}\n```\n\nThe three AgentOS statuses are for:\n\n- unauthenticated `GET /api/agents`;\n- unauthenticated `POST /api/chat`;\n- wrong-bearer `POST /api/chat`.\n\nThe side-effect list proves both unauthenticated chat requests invoked the\nagent method.\n\nMinimal inline reproducer:\n\n```python\nfrom pathlib import Path\nfrom tempfile import TemporaryDirectory\n\nfrom fastapi.testclient import TestClient\nfrom praisonai import AgentApp\nfrom praisonaiagents import AgentOSConfig\n\nclass StubAgent:\n    name = \"pov_agentos_agent\"\n    role = \"tester\"\n    instructions = \"private instruction marker\"\n\n    def __init__(self, out):\n        self.out = out\n\n    def chat(self, message):\n        self.out.write_text(self.out.read_text() + message + \"\\n\")\n        return \"PRAI_CAND_007_AGENTOS_EXECUTED:\" + message\n\nwith TemporaryDirectory() as tmp:\n    side_effect = Path(tmp) / \"side_effects.txt\"\n    side_effect.write_text(\"\")\n    app = AgentApp(\n        agents=[StubAgent(side_effect)],\n        config=AgentOSConfig(host=\"0.0.0.0\", port=8000),\n    )\n    client = TestClient(app.get_app())\n\n    assert client.get(\"/api/agents\").status_code == 200\n    assert client.post(\"/api/chat\", json={\"message\": \"no-auth\"}).status_code == 200\n    assert client.post(\n        \"/api/chat\",\n        headers={\"Authorization\": \"Bearer definitely-wrong\"},\n        json={\"message\": \"wrong-bearer\"},\n    ).status_code == 200\n    assert side_effect.read_text().splitlines() == [\"no-auth\", \"wrong-bearer\"]\n```\n\n## Version Sweep\n\n| Target | Result |\n| --- | --- |\n| `v4.5.126` | vulnerable |\n| `v4.5.128` | vulnerable |\n| `v4.6.9` | vulnerable |\n| `v4.6.10` | vulnerable |\n| `v4.6.56` | vulnerable; generated deploy API control returns `401/401/200` |\n| `v4.6.57` | vulnerable; generated deploy API control returns `401/401/200` |\n| current `2f9677abb` | vulnerable; generated deploy API control returns `401/401/200` |\n\nEvidence files are retained locally under the bundle's `evidence/` directory\nand can be provided if useful.\n\n## Duplicate / Incomplete-Fix Notes\n\nThis report is related to `GHSA-pm96-6xpr-978x` / `CVE-2026-40151`. The\npublished advisory describes AgentOS instruction disclosure and lists\n`4.5.128` as patched. It also mentions unauthenticated `/api/chat` as a chained\ninstruction-extraction path.\n\nThe current report should be treated as an incomplete fix / affected-range\ncorrection with a broader demonstrated impact:\n\n- the published patched version `v4.5.128` still reproduces;\n- latest release `v4.6.57` still reproduces;\n- current main still reproduces;\n- the PoV proves unauthorized agent invocation and side effects, not only\n  instruction disclosure.\n\nThis is distinct from private `PRAI-CAND-003` / `GHSA-x8cv-xmq7-p8xp`, which\ncovers `praisonaiagents.AgentTeam.launch()` routes. This report covers\n`praisonai.app.AgentOS` and `AgentApp` alias routes.\n\n## Impact\n\nIf an operator exposes an AgentOS app on a reachable interface, any client that\ncan reach it can:\n\n- enumerate deployed agents through `GET /api/agents`;\n- read agent names, roles, and instruction snippets;\n- invoke the default agent or a named agent through `POST /api/chat`;\n- trigger downstream tools, private context reads, memory accesses, API\n  integrations, browser actions, or other side effects attached to the agent;\n- consume model/API budget through repeated invocation.\n\nThe exact downstream impact depends on the deployed agents. The framework-level\nboundary failure is that a production deployment surface exposes agent control\nwithout authentication and defaults to binding on all interfaces.\n\n## Suggested Fix\n\nUse the same security model already applied to generated API deployments:\n\n- add authentication fields to `AgentOSConfig` / `AgentAppConfig`;\n- default auth to enabled;\n- default bind host to `127.0.0.1`;\n- reject no-auth and wrong-bearer requests for `GET /api/agents` and\n  `POST /api/chat`;\n- fail closed for non-loopback binds unless auth is configured or an explicit\n  unsafe development opt-out is set;\n- avoid returning instruction text from unauthenticated metadata endpoints;\n- add regression tests for no auth, wrong bearer, correct bearer, and external\n  bind without auth.\n\nMaintainers can either update `GHSA-pm96-6xpr-978x` with the corrected affected\nrange and broader impact or publish a separate incomplete-fix advisory.\n\n## Suggested Severity\n\nSuggested severity: Critical.\n\nThe Critical score matches the unauthenticated agent-control model: network\nattacker, low complexity, no privileges, no user interaction, and high\ndeployment-dependent impact when agents are connected to tools, private data,\nor cost-bearing services. If maintainers score only a minimal no-tool demo\nagent, the impact may be lower, but the current default framework behavior is\nstill unauthenticated agent invocation.","aliases":["CVE-2026-57116","GHSA-892r-p3jq-jp24"],"modified":"2026-07-23T15:00:20.690939654Z","published":"2026-07-23T11:41:42.115081Z","references":[{"type":"WEB","url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-892r-p3jq-jp24"},{"type":"PACKAGE","url":"https://github.com/MervinPraison/PraisonAI"},{"type":"PACKAGE","url":"https://pypi.org/project/praisonai"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-892r-p3jq-jp24"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57116"}],"affected":[{"package":{"name":"praisonai","ecosystem":"PyPI","purl":"pkg:pypi/praisonai"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.2.1"},{"fixed":"4.6.59"}]}],"versions":["4.2.1","4.2.2","4.2.3","4.2.4","4.3.0","4.3.1","4.4.0","4.4.10","4.4.11","4.4.12","4.4.2","4.4.3","4.4.4","4.4.5","4.4.6","4.4.7","4.4.8","4.4.9","4.5.0","4.5.1","4.5.10","4.5.100","4.5.101","4.5.102","4.5.103","4.5.104","4.5.105","4.5.106","4.5.107","4.5.108","4.5.109","4.5.11","4.5.110","4.5.111","4.5.112","4.5.113","4.5.114","4.5.115","4.5.117","4.5.118","4.5.119","4.5.12","4.5.120","4.5.121","4.5.122","4.5.123","4.5.124","4.5.125","4.5.126","4.5.127","4.5.128","4.5.129","4.5.13","4.5.130","4.5.131","4.5.132","4.5.133","4.5.134","4.5.135","4.5.136","4.5.137","4.5.139","4.5.14","4.5.140","4.5.143","4.5.144","4.5.145","4.5.149","4.5.15","4.5.16","4.5.18","4.5.19","4.5.2","4.5.20","4.5.21","4.5.22","4.5.23","4.5.24","4.5.25","4.5.26","4.5.27","4.5.28","4.5.29","4.5.3","4.5.30","4.5.31","4.5.32","4.5.33","4.5.34","4.5.35","4.5.36","4.5.37","4.5.38","4.5.39","4.5.40","4.5.41","4.5.42","4.5.43","4.5.44","4.5.45","4.5.46","4.5.48","4.5.49","4.5.5","4.5.51","4.5.52","4.5.54","4.5.55","4.5.56","4.5.57","4.5.58","4.5.59","4.5.6","4.5.60","4.5.62","4.5.63","4.5.64","4.5.65","4.5.67","4.5.68","4.5.69","4.5.7","4.5.70","4.5.71","4.5.72","4.5.73","4.5.74","4.5.76","4.5.77","4.5.78","4.5.79","4.5.8","4.5.80","4.5.81","4.5.82","4.5.83","4.5.85","4.5.87","4.5.88","4.5.89","4.5.9","4.5.90","4.5.93","4.5.94","4.5.95","4.5.96","4.5.97","4.5.98","4.6.10","4.6.11","4.6.12","4.6.13","4.6.14","4.6.15","4.6.16","4.6.18","4.6.19","4.6.20","4.6.21","4.6.22","4.6.23","4.6.24","4.6.25","4.6.26","4.6.27","4.6.28","4.6.29","4.6.30","4.6.31","4.6.32","4.6.33","4.6.34","4.6.35","4.6.36","4.6.37","4.6.38","4.6.39","4.6.40","4.6.41","4.6.42","4.6.43","4.6.44","4.6.45","4.6.46","4.6.47","4.6.48","4.6.50","4.6.51","4.6.52","4.6.53","4.6.54","4.6.55","4.6.56","4.6.57","4.6.58","4.6.9"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/praisonai/PYSEC-2026-3507.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}