Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cwj8-7gp2-ggcw | praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery |
Tue, 15 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run when PLATFORM_ENV is also unset because that setting defaults to dev. A remote unauthenticated attacker can mint an HS256 token with an arbitrary sub and email, and the platform's AuthService._verify_token() and get_current_user dependency accept the forged identity for protected API routes. This vulnerability is fixed in praisonai-platform 0.1.6. | |
| Title | praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery | |
| Weaknesses | CWE-1188 CWE-798 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T10:34:16.300Z
Reserved: 2026-06-24T01:45:48.697Z
Link: CVE-2026-57147
No data.
Status : Deferred
Published: 2026-09-15T11:17:11.760
Modified: 2026-09-15T14:45:28.563
Link: CVE-2026-57147
No data.
OpenCVE Enrichment
No data.
Github GHSA