CVE-2026-57148 | MervinPraison PraisonAI up to 0.1.5 Authentication Service auth_service.py AuthService._verify_token sub improper authentication

SecurityVulns

A vulnerability categorized as critical has been discovered in MervinPraison PraisonAI up to 0.1.5. Affected by this vulnerability is the function AuthService._verify_token of the file praisonai_platform/services/auth_service.py of the component Authentication Service. The manipulation of the argument sub results in improper authentication.

This vulnerability was named CVE-2026-57148. The attack may be performed from remote. There is no available exploit.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More