/Vulnerability Library

PraisonAI AgentOS - Information Disclosure

CVE-2026-40151
Verified

Description

PraisonAI's AgentOS FastAPI application server exposes an unauthenticated `GET /api/agents` endpoint that lists every registered agent's name, role and the opening of its instructions (system prompt). No authentication is enforced on the route, allowing a remote attacker to enumerate agent configurations and harvest sensitive details embedded in system prompts, such as internal API references, business logic and credential hints. This endpoint belongs to the AgentOS FastAPI server and is distinct from the legacy Flask `/agents` server tracked as CVE-2026-44338.

Severity

Medium

CVSS Score

5.3

Exploit Probability

1%

Affected Product

praisonai

Published Date

June 1, 2026

Template Author

aryu-ru

CVE-2026-40151.yaml
5.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE ID:
cve-2026-40151
CWE ID:
cwe-200

References

https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-pm96-6xpr-978xhttps://nvd.nist.gov/vuln/detail/CVE-2026-40151

Remediation Steps

Upgrade PraisonAI to version 4.5.128 or later and restrict network access to the AgentOS API.