Mehrere Schwachstellen (CVE-2026-47393, CVE-2026-47396, CVE-2026-64824, CVE-2026-64825) in Praisonai

Mervinpraison - Praisonai - CRITICAL - CVE-2026-47396. PraisonAI's call server is susceptible to unauthorized access due to a lack of authentication mechanisms when the `CALL_SERVER_TOKEN` is not set. This flaw allows any client with network access to exploit critical agent control endpoints available through the `praisonai.api.agent_invoke` router. Specifically, when launched without an explicit token, operators inadvertently expose sensitive functionalities, including the ability to list agents, inspect metadata, invoke, and unregister agents. To mitigate this risk, it is crucial for users to upgrade to version 4.6.40 or later, where this vulnerability has been addressed.
Quelle: securityvulnerability.io