External risk intelligence

PraisonAI API Unauthenticated Job Creation and Control Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-57131

The vulnerability exists in an API endpoint (/api/v1/runs) within a multi-agent system. Such API interfaces are commonly deployed as network-accessible services to facilitate remote agent interactions and job management, making them likely to be exposed to the network in standard deployments of this technology.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in the PraisonAI multi-agent system allows unauthenticated network access to sensitive job functions, potentially exposing service credentials and enabling unauthorized agent execution by controlling prompts and configurations. This issue could allow unauthorized access to system capabilities if the affected component is exposed externally.

  • Unauthorized access to agent jobs and credentials.
  • Critical security flaw impacts multi-agent systems.
  • Confirm exposure and review system controls.

Attack Path

How an attacker could exploit the issue

An attacker can reach the vulnerable component by interacting with the system's API over the network. This exposed API endpoint allows for the submission of prompts and agent configurations, and the management of jobs without requiring authentication or specific job authorization. When exploited, this can lead to unauthorized agent execution, exposing service credentials and tool capabilities.

  • No authentication required for API access.
  • Submitting attacker-controlled prompts triggers vulnerability.
  • Risk includes unauthorized agent execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, unauthorized network clients could submit attacker-controlled prompts and agent configurations to the PraisonAI system. This could expose service credentials and connected tool capabilities, leading to unauthorized agent execution.

  • Service credentials and tool capabilities at risk.
  • Unauthenticated API endpoints allow prompt submission.
  • Unauthorized agent execution could occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in PraisonAI's job server could allow unauthorized access and control of agent execution and connected tools. Responsibility likely falls to the platform team managing the PraisonAI deployment and the security team responsible for network access controls. The first step is to identify all instances of PraisonAI, confirm their network exposure and business criticality, and then assign ownership for remediation planning.

  • Platform and security teams own the issue.
  • Verify PraisonAI instances and exposure.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is PraisonAI?

PraisonAI is a framework designed to build and manage multi-agent systems. It allows users to orchestrate autonomous agents that work together to perform tasks. By coordinating these agents through a central job server, the platform enables automated workflows, prompt processing, and the integration of various external tools and service credentials to complete complex objectives.

What does CVE-2026-57131 mean for security?

This vulnerability involves a failure to verify the identity of users or their permissions when interacting with specific API endpoints. Classified under weakness categories like missing authentication and authorization, it allows unauthorized parties to bypass security controls. Essentially, the system treats unverified requests as legitimate, granting external actors control over agent tasks, configurations, and sensitive tool capabilities.

How can an attacker trigger this vulnerability?

An attacker triggers this issue by sending unauthenticated requests directly to the API endpoint responsible for job management. Because the system lacks necessary checks, simply interacting with the exposed path allows an outsider to submit custom prompts or modify agent behavior. Please note that normal, authorized internal use of the agent system does not trigger this flaw; the vulnerability is specifically opened by the absence of identity validation for external network requests.

Is my instance of PraisonAI at risk?

If your deployment is accessible over the network, Halo Surface Signal identifies it as a likely target because the vulnerable API endpoints are typically exposed to support remote interactions. Systems that are reachable from the internet or broad internal networks are at higher risk. If the PraisonAI instance is isolated from the network and restricted only to trusted local users, the potential for unauthorized external exploitation is significantly reduced.

What should I do to secure my system?

Your first step is to identify all running instances of PraisonAI within your infrastructure and confirm their current network accessibility. Once identified, prioritize updating to version 4.6.58 or later, as this release includes the necessary fixes to enforce authentication. While planning your update, ensure that network-level access controls are strictly configured to limit exposure to only those users and systems that absolutely require it.

References