External risk intelligence

PraisonAI AgentOS Unauthenticated API Access Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-57140

The vulnerability affects an API service (AgentOS) that binds to 0.0.0.0 by default and exposes unauthenticated endpoints for agent interaction. As a multi-agent system providing API and chat interfaces, this product is commonly deployed as an externally accessible service or API endpoint, making it likely to be reachable from the network.

Missing Authentication

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the AgentOS component of PraisonAI, affecting versions prior to 1.7.2. This issue allows unauthorized remote access to agent information and the ability to invoke agents, potentially exposing sensitive data, credentials, and workflow states. The primary concern is to confirm if our deployment is within the vulnerable version range and assess potential exposure.

  • Unsecured AI agents can be accessed remotely.
  • Sensitive data and AI functions may be compromised.
  • Confirm relevance and verify unaffected systems.

Attack Path

How an attacker could exploit the issue

An attacker could access the AgentOS API if it's exposed externally. By sending specially crafted requests to the `/api/agents` or `/api/chat` endpoints, an unauthenticated attacker can discover agent details and then invoke agents. This allows them to potentially interact with an agent's tools, memory, external services, or sensitive credentials.

  • Attacker can reach the exposed service.
  • Unauthenticated API endpoints are triggered.
  • Leads to information disclosure and unauthorized actions.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthorized access to agent information and the invocation of agent functionalities. A remote caller who can reach the service may obtain agent names, roles, and instruction prefixes. When supported, this could lead to the execution of agent actions, potentially affecting its tools, memory, external APIs, credentials, and workflow state.

  • Agent information and capabilities.
  • Unauthenticated API endpoints.
  • Compromised agent workflows.

Operational Fix

Recommended remediation, mitigation, and detection steps

The PraisonAI AgentOS, specifically versions prior to 1.7.2, exposes unauthenticated API endpoints that could allow remote attackers to access sensitive agent information and execute actions. Application owners and platform teams are likely responsible for addressing this. The first step is to identify all deployments of the affected technology, determine their reachability and business criticality, and then plan remediation, potentially involving vendor coordination for updates.

  • Application owners must confirm exposures.
  • Verify agent reachability and criticality.
  • Plan vendor-coordinated updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is PraisonAI and the AgentOS component?

PraisonAI is a framework designed for building and managing multi-agent systems where AI agents collaborate to perform tasks. AgentOS is the specific component within this platform that handles the underlying orchestration, API communication, and agent lifecycle. Users rely on this technology to integrate AI agents into workflows, allowing them to access memory, external tools, and business logic through structured API endpoints.

What does CVE-2026-57140 mean for security?

This vulnerability is classified as CWE-306, which refers to Missing Authentication for Critical Function. It means the software performs sensitive operations, such as interacting with AI agents or retrieving system information, without verifying who is making the request. In the context of this CVE, it allows an unauthorized person to treat the system as if they were an authenticated user.

How is the AgentOS API triggered by an attacker?

The vulnerability is triggered by sending standard network requests to specific unauthenticated endpoints, such as the API for agent information or chat functions. Simply having the service running and reachable is sufficient for an attacker; no special or complex exploit code is needed to interact with the API. It is not triggered if the service is configured to bind only to local interfaces or is protected by network-level access controls.

Do I need to worry about this CVE?

You should prioritize this if your PraisonAI instance is network-reachable. Halo Surface Signal notes that because AgentOS binds to all network interfaces (0.0.0.0) by default and provides API functionality, it is frequently deployed in ways that make it accessible from the internet. If your deployment is exposed to the wider network rather than restricted to internal, private segments, the risk of unauthorized access is significantly higher.

How can I fix this PraisonAI vulnerability?

Your first step is to inventory all systems running PraisonAI to see if they are using a version earlier than 1.7.2. If you are on an affected version, upgrade to 1.7.2 or later, which introduced the necessary authentication middleware. Until you can update, ensure that the AgentOS service is strictly isolated from the internet and that access is restricted to authorized network segments only.

References