CVE-2026-57127 is a fail-open authentication vulnerability in the PraisonAI praisonai package affecting recipe serve middleware. When authentication is configured to use API key or JWT, the middleware silently disables authentication if the corresponding secret is not configured. As a result, requests to recipe execution endpoints may be processed without any authentication despite the deployment being configured for protected access. The flaw is rooted in authentication initialization logic that does not fail closed when required secret material is absent, causing protected endpoints to become unintentionally unauthenticated.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
auth: api-key or auth: jwt explicitly defines the corresponding secret through supported configuration fields or environment variables before exposing the service. Do not expose recipe serve endpoints to untrusted networks unless authentication has been verified to be enforced. Where possible, add deployment-side validation or wrapper checks that reject startup when authentication is enabled but secret configuration is absent.Patch, then assume compromise.
praisonai package to version 4.6.59 or later. If immediate upgrade is not possible, change the authentication middleware behavior so that startup fails whenever auth_type is configured as api-key or jwt but the required secret is missing. This should enforce fail-closed behavior and prevent the service from starting in an unauthenticated state.No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.