Skip to content

🔒 Security: Hardcoded credentials found (PostHog API Key, WhatsApp token, JWT secret default) #3479

Description

@Correctover

Summary

Hi @MervinPraison 👋

We discovered 3 security vulnerabilities in PraisonAI related to hardcoded credentials and predictable defaults. Since your SECURITY.md recommends private disclosure, we are opening this issue to ask: what is the best email address to send the full security report to?

We would like to share the complete details (affected files, line numbers, CVSS scores, and fix suggestions) via email for responsible disclosure.

Brief Overview

# Issue Severity Location
1 Hardcoded PostHog API Key in telemetry module High (CVSS 8.5) praisonaiagents/telemetry/telemetry.py
2 Hardcoded WhatsApp verify token in example code Medium (CVSS 5.3) praisonai_bot/bots/whatsapp.py
3 Predictable default JWT secret in platform module Medium (CVSS 6.5) praisonai_platform/services/jwt_secret.py

All issues have been verified against the latest code on the main branch.

Request

Could you please provide a security contact email so we can send the full report with reproduction steps and fix suggestions?

Thank you for your time!


Discovered by Correctover — AI Reliability Infrastructure

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions