PraisonAI versions before 4.6.78 are affected by CVE-2026-61435, an authentication bypass in the Call API agent invocation functionality. The flaw appears when PRAISONAI_CALL_AUTH=disabled is configured: the application tries to restrict unauthenticated access to localhost, but determines the request origin from the client-controlled HTTP Host header via request.url.hostname, allowing an attacker to spoof 127.0.0.1 and appear local.
A remote unauthenticated attacker who can reach the service can exploit the issue to access agent-related endpoints without logging in, including GET /api/v1/agents to enumerate registered agents and POST /api/v1/agents/{agent_id}/invoke to invoke them. The vulnerable logic is reported in src/praisonai/praisonai/api/agent_invoke.py; the issue is classified as CWE-287 and carries a CVSS v3.1 score vector of AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N, indicating low-complexity network exploitation with high integrity impact.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
A vulnerability affecting PraisonAI before version 4.6.78 was disclosed in which a remote unauthenticated attacker can spoof the HTTP Host header as 127.0.0.1 to bypass localhost-only restrictions when PRAISONAI_CALL_AUTH is disabled. The flaw allows unauthorized listing of registered agents and invocation of agent-related API endpoints.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
vulncheck.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.