SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-57131

CRITICAL · CVSS 9.8 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

PraisonAI versions prior to 4.6.58 are vulnerable due to a lack of authentication and per-job authorization in the praisonai.jobs.server.create_app endpoint, allowing unauthorized network clients to manipulate job submissions and access sensitive service credentials. The critical impact includes the potential for unauthorized agent execution, job management, and exposure of connected tool capabilities. Organizations using affected versions should prioritize immediate updates to version 4.6.58 or later to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57131
Severity
CRITICAL
CVSS
9.8
EPSS
N/A

Original NVD Description

PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker-controlled prompts and agent configuration, list and read jobs, stream results, and cancel or delete other jobs, exposing service credentials and connected tool capabilities to unauthorized agent execution. This vulnerability is fixed in 4.6.58.