info: name: praisonai cve: CVE-2026-47410 summary: PraisonAI Platform hardcoded JWT signing secret leads to authentication bypass details: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcoded literal "dev-secret-change-me" when PLATFORM_JWT_SECRET is unset. A safety check exists but only fires when PLATFORM_ENV != "dev"; the default value of PLATFORM_ENV is "dev", so the check is silently bypassed in any deployment that does not explicitly opt out. An attacker who discovers the hardcoded secret can forge valid JWT tokens, impersonate any user, and gain full access to the platform's authentication-protected endpoints without any legitimate credentials. This vulnerability has a CVSS v3.1 score of 9.8 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The fix in PraisonAI Platform version 0.1.4 removes the hardcoded default and requires explicit configuration of PLATFORM_JWT_SECRET, while also changing PLATFORM_ENV default to "production" so the safety check is no longer silently bypassed. cvss: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H severity: CRITICAL security_advise: Upgrade PraisonAI Platform to version 0.1.4 or later. Ensure PLATFORM_JWT_SECRET is explicitly set to a strong, unique secret in all deployment environments, and set PLATFORM_ENV to "production" (or any non-"dev" value) to enforce the safety check. rule: version < "0.1.4" references: - https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-3qg8-5g3r-79v5 - https://github.com/MervinPraison/PraisonAI/commit/ef79b7a0561796ad9807f0f09538c25cc78d3619 - https://nvd.nist.gov/vuln/detail/CVE-2026-47410 - https://github.com/MervinPraison/PraisonAI/pull/1685