PatchSiren cyber security CVE debrief
CVE-2026-61435 MervinPraison CVE debrief
CVE-2026-61435 is a vulnerability in PraisonAI's n8n/call agent invocation API. The patched `PRAISONAI_CALL_AUTH=disabled` safeguard can be bypassed with a spoofed `Host: 127.0.0.1` header, allowing an unauthenticated network caller to list and invoke registered agents when the service is reachable and the opt-out is enabled. This vulnerability affects PraisonAI deployments, particularly those with exposed API endpoints. Defenders should assess exposure and prioritize patching to prevent potential authentication bypass.
- Vendor
- MervinPraison
- Product
- praisonai
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for PraisonAI deployments should assess exposure and prioritize patching to prevent potential authentication bypass. This includes reviewing the affected versions of PraisonAI, applying the patch, and verifying that the API is not exposed to untrusted networks. Additionally, defenders should monitor the API for suspicious activity and review compensating controls for exposed systems.
Why it matters
CVE-2026-61435 is a vulnerability in PraisonAI's n8n/call agent invocation API that allows an unauthenticated network caller to list and invoke registered agents when the service is reachable and the opt-out is enabled.
- An unauthenticated network caller can list registered agents.
- An unauthenticated network caller can invoke registered agents.
- Defenders should verify the affected versions of PraisonAI and apply the patch.
Technical summary
The vulnerability is caused by a flawed implementation of the `verify_token()` function in `src/praisonai/praisonai/api/agent_invoke.py`. The function does not properly validate the `Host` header, allowing an attacker to bypass authentication. This issue arises when the `PRAISONAI_CALL_AUTH=disabled` safeguard is enabled, which is intended to disable authentication for localhost bindings. However, due to the spoofable nature of the `Host` header, an unauthenticated network caller can exploit this vulnerability to list and invoke registered agents.
Defensive priority
Defenders should prioritize verifying the affected versions of PraisonAI and applying the patch to prevent potential authentication bypass.
Recommended defensive actions
- Verify the version of PraisonAI and apply the patch to prevent potential authentication bypass.
- Restrict access to the n8n/call agent invocation API to only trusted hosts.
- Monitor the API for suspicious activity.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability is caused by a flawed implementation of the `verify_token()` function in `src/praisonai/praisonai/api/agent_invoke.py`. The function does not properly validate the `Host` header, allowing an attacker to bypass authentication.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-61435 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-61435
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-61435 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61435
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
PraisonAI: Call API localhost-only authentication bypass via spoofed Host header
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-2gpf-2492-q9jh.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2gpf-2492-q9jh
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62174
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/MervinPraison/PraisonAI/commit/2a855c470077c7d2e2479a575f7ef7f548d51c33
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/MervinPraison/PraisonAI
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/praisonai-before-authentication-bypass-via-host-header-spoofing
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.