漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
Vulnerability Description
PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key but _create_agents_app() does not authenticate POST /agents or POST /agents/{agent_name}. A network caller can invoke configured agents without credentials even when an API key was supplied. This issue is fixed in version 4.6.58.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Vulnerability Type
关键功能的认证机制缺失
Vulnerability Title
Mervin Praison PraisonAI 授权问题漏洞
Vulnerability Description
Mervin Praison PraisonAI是Mervin Praison个人开发者开源的一个低代码多智能体协作框架。 Mervin Praison PraisonAI 4.6.34版本至4.6.58之前版本存在授权问题漏洞,该漏洞源于未对POST /agents和POST /agents/{agent_name}接口进行身份验证,可能导致网络攻击者在未提供凭据的情况下调用已配置的代理。
CVSS Information
N/A
Vulnerability Type
N/A