CVE-2026-47410
PraisonAI Platform versions before 0.1.4 use a hard‑coded JWT signing key that is publicly visible. An attacker can read this key, forge JSON Web Tokens, and impersonate any user, including administrators. The issue is fixed in version 0.1.4.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
PraisonAI Platform versions prior to 0.1.4. Typical users are teams deploying the platform without setting a custom JWT secret.
Real-world impact
An attacker can create valid tokens and gain full access to any account, including workspace owners and admins, effectively taking over the entire platform.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is exploitable over the network with no authentication, provides complete compromise of confidentiality, integrity, and availability, and requires no user interaction.
What to do about it
- 01Upgrade PraisonAI Platform to version 0.1.4 or later.
- 02Restart the platform service to apply the new configuration.
NVD-referenced vendor advisory
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.