CVE-2026-57147Critical· 9.8▾ AbyssalPoC availablePraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run whe…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 53.9 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.5%
Last analysed / modified upstream
0.5% → 0.8%
Exploit / PoC code exists
PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run when PLATFORM_ENV is also unset because that setting defaults to dev. A remote unauthenticated attacker can mint an HS256 token with an arbitrary sub and email, and the platform's AuthService._verify_token() and get_current_user dependency accept the forged identity for protected API routes. This vulnerability is fixed in praisonai-platform 0.1.6.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
praisonai-platform < 0.1.6Patched in:
praisonai-platform 0.1.6Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57148Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-57127Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-57126High· 8.5PraisonAI is a multi-agent teams system
CVE-2026-57112High· 8.3PraisonAI is a multi-agent teams system
CVE-2026-57124Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-57119High· 7.5PraisonAI is a multi-agent teams system