Back

CRITICAL

praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery

Published Sep 15, 2026

Description

PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run when PLATFORM_ENV is also unset because that setting defaults to dev. A remote unauthenticated attacker can mint an HS256 token with an arbitrary sub and email, and the platform's AuthService._verify_token() and get_current_user dependency accept the forged identity for protected API routes. This vulnerability is fixed in praisonai-platform 0.1.6.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Sep 15, 2026
Updated Sep 17, 2026
Reserved Jun 24, 2026

CISA Vulnrichment

Updated Sep 17, 2026

NVD

Status Deferred
Modified Sep 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Sep 15, 2026
Updated Sep 17, 2026