Disclosure summary
## Summary The AgentOS server in the `praisonai` TypeScript/npm package ships an insecure default: it binds `0.0.0.0`, sets no API key, and uses CORS `*` with credentials. The API-key middleware is only registered when an API key is configured, so the documented quickstart (`new AgentOS({agents:[...]}).serve({port})`) exposes, **unauthenticated**, `GET /api/agents` (which leaks agent names/roles/instructions, i.e. system prompts) and `POST /api/chat` (which invokes agents). Any network peer can read agent system prompts and drive the agent. Runtime-confirmed; severity High. ## Details ### Affected component - Package: `praisonai` (npm / TypeScript). Files `src/praisonai-ts/src/os/config.ts` and `src/praisonai-ts/src/os/agentos.ts` (`AgentOS`). ### Vulnerable code / root cause Path: `src/praisonai-ts/src/os/config.ts` Class/const: `DEFAULT_AGENTOS_CONFIG` / `mergeConfig` Snippet: ```ts export const DEFAULT_AGENTOS_CONFIG = { host: '0.0.0.0', corsOrigins: ['*'], apiKey: '', // ... }; // mergeConfig: apiKey = userConfig?.apiKey ?? process.env.PRAISONAI_AGENTOS_API_KEY ?? ''; ``` Issue: defaults bind all interfaces, with an empty API key and wildcard CORS. `apiKey` stays empty unless t
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-6wjp-v33h-5cvq
Open original source · Updated Oct 08, 2026
PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosure
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | praisonai | < 1.7.3 | 1.7.3 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-08T18:01:29-04:00
MODIFIED 2026-10-08T18:01:31-04:00
INGESTED 2026-10-10T20:45:43-04:00