Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in the AgentOS component of PraisonAI, affecting versions prior to 1.7.2. This issue allows unauthorized remote access to agent information and the ability to invoke agents, potentially exposing sensitive data, credentials, and workflow states. The primary concern is to confirm if our deployment is within the vulnerable version range and assess potential exposure.
- Unsecured AI agents can be accessed remotely.
- Sensitive data and AI functions may be compromised.
- Confirm relevance and verify unaffected systems.
Attack Path
How an attacker could exploit the issue
An attacker could access the AgentOS API if it's exposed externally. By sending specially crafted requests to the `/api/agents` or `/api/chat` endpoints, an unauthenticated attacker can discover agent details and then invoke agents. This allows them to potentially interact with an agent's tools, memory, external services, or sensitive credentials.
- Attacker can reach the exposed service.
- Unauthenticated API endpoints are triggered.
- Leads to information disclosure and unauthorized actions.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow unauthorized access to agent information and the invocation of agent functionalities. A remote caller who can reach the service may obtain agent names, roles, and instruction prefixes. When supported, this could lead to the execution of agent actions, potentially affecting its tools, memory, external APIs, credentials, and workflow state.
- Agent information and capabilities.
- Unauthenticated API endpoints.
- Compromised agent workflows.
Operational Fix
Recommended remediation, mitigation, and detection steps
The PraisonAI AgentOS, specifically versions prior to 1.7.2, exposes unauthenticated API endpoints that could allow remote attackers to access sensitive agent information and execute actions. Application owners and platform teams are likely responsible for addressing this. The first step is to identify all deployments of the affected technology, determine their reachability and business criticality, and then plan remediation, potentially involving vendor coordination for updates.
- Application owners must confirm exposures.
- Verify agent reachability and criticality.
- Plan vendor-coordinated updates.