PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-61435 MervinPraison CVE debrief

CVE-2026-61435 is a vulnerability in PraisonAI's n8n/call agent invocation API. The patched `PRAISONAI_CALL_AUTH=disabled` safeguard can be bypassed with a spoofed `Host: 127.0.0.1` header, allowing an unauthenticated network caller to list and invoke registered agents when the service is reachable and the opt-out is enabled. This vulnerability affects PraisonAI deployments, particularly those with exposed API endpoints. Defenders should assess exposure and prioritize patching to prevent potential authentication bypass.

Vendor
MervinPraison
Product
praisonai
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for PraisonAI deployments should assess exposure and prioritize patching to prevent potential authentication bypass. This includes reviewing the affected versions of PraisonAI, applying the patch, and verifying that the API is not exposed to untrusted networks. Additionally, defenders should monitor the API for suspicious activity and review compensating controls for exposed systems.

Why it matters

CVE-2026-61435 is a vulnerability in PraisonAI's n8n/call agent invocation API that allows an unauthenticated network caller to list and invoke registered agents when the service is reachable and the opt-out is enabled.

  • An unauthenticated network caller can list registered agents.
  • An unauthenticated network caller can invoke registered agents.
  • Defenders should verify the affected versions of PraisonAI and apply the patch.

Technical summary

The vulnerability is caused by a flawed implementation of the `verify_token()` function in `src/praisonai/praisonai/api/agent_invoke.py`. The function does not properly validate the `Host` header, allowing an attacker to bypass authentication. This issue arises when the `PRAISONAI_CALL_AUTH=disabled` safeguard is enabled, which is intended to disable authentication for localhost bindings. However, due to the spoofable nature of the `Host` header, an unauthenticated network caller can exploit this vulnerability to list and invoke registered agents.

Defensive priority

Defenders should prioritize verifying the affected versions of PraisonAI and applying the patch to prevent potential authentication bypass.

Recommended defensive actions

  • Verify the version of PraisonAI and apply the patch to prevent potential authentication bypass.
  • Restrict access to the n8n/call agent invocation API to only trusted hosts.
  • Monitor the API for suspicious activity.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability is caused by a flawed implementation of the `verify_token()` function in `src/praisonai/praisonai/api/agent_invoke.py`. The function does not properly validate the `Host` header, allowing an attacker to bypass authentication.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-61435 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-61435

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-61435 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61435

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • PraisonAI: Call API localhost-only authentication bypass via spoofed Host header

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/PyPI/GHSA-2gpf-2492-q9jh.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2gpf-2492-q9jh

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62174

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MervinPraison/PraisonAI/commit/2a855c470077c7d2e2479a575f7ef7f548d51c33

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/MervinPraison/PraisonAI

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/praisonai-before-authentication-bypass-via-host-header-spoofing

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.