CVE-2026-47396
PraisonAI’s call server can be run without authentication if the CALL_SERVER_TOKEN is not set, exposing a network‑facing API that lets anyone control agents. This flaw allows attackers to list, inspect, invoke, or delete agents from any reachable host. The issue is fixed in version 4.6.40.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
PraisonAI, versions earlier than 4.6.40, especially users who start the call server without configuring CALL_SERVER_TOKEN.
Real-world impact
An attacker who can reach the call server can enumerate all agents, view their instructions and metadata, trigger agent actions, and even remove agents, effectively taking full control of the system’s agent layer.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is network‑exposed, requires no authentication, and gives attackers complete compromise of confidentiality, integrity, and availability of the agent control plane.
What to do about it
- 01Upgrade PraisonAI to version 4.6.40 or later.
- 02Restart the call server after the upgrade.
NVD-referenced vendor advisory
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.