CVE-2026-56076: PraisonAI - Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint

Published Jun 18, 2026
·
Updated

PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attackers to trigger arbitrary agent execution. The POST /agui endpoint lacks authentication and hardcodes Access-Control-Allow-Origin: headers, combined with Starlette's Content-Type-agnostic JSON parsing, enabling attackers to bypass CORS preflight checks via simple requests and exfiltrate sensitive agent responses including tool execution results and environment data.

Affected Software

1 affected component
PraisonAI praisonai<1.5.128

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade PraisonAI to a version that resolves this vulnerability.

    Fixed in 1.5.128
  2. Configuration

    Require authentication on the POST /agui endpoint so remote attackers cannot trigger agent execution without valid credentials.

    PraisonAI AGUI endpoint (/agui) authentication = required
  3. Configuration

    Remove the hardcoded Access-Control-Allow-Origin: * response header on the /agui endpoint and configure CORS to allow only explicitly authorized origins.

    PraisonAI AGUI endpoint (/agui) Access-Control-Allow-Origin = not *
  4. Compensating control

    If CORS must be permissive for compatibility, add an external compensating control (e.g., restrict which origins can reach the AGUI endpoint via network allowlisting/WAF/ACL) to limit cross-origin access.

Event History

Jun 18, 2026
CVE Published
via MITRE·10:12 PM
Data Sourced
via MITRE·10:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-56076?

The severity of CVE-2026-56076 is high, with a CVSS score of 8.1.

2

How do I fix CVE-2026-56076?

To fix CVE-2026-56076, update to PraisonAI version 1.5.128 or later, which addresses the cross-origin agent execution vulnerability.

3

What are the potential impacts of CVE-2026-56076?

CVE-2026-56076 can allow remote attackers to execute arbitrary agents due to missing authentication and hardcoded wildcard CORS settings.

4

Which component is affected by CVE-2026-56076?

The affected component of CVE-2026-56076 is the AGUI endpoint in PraisonAI.

5

What actions can attackers perform due to CVE-2026-56076?

Attackers can exploit CVE-2026-56076 to trigger arbitrary agent execution without authentication.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203