GHSA-8ccj-p46r-jwqq: PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication
Setting PRAISONAI_CALL_AUTH=disabled completely disables all authentication on the /api/v1/agents/{id}/invoke endpoint. This bypass is advertised in the application’s own error messages, making it likely to appear in production Docker and Compose configurations.
References
Code Behaviors & Features
Detect and mitigate GHSA-8ccj-p46r-jwqq with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →