Summary
Hi @MervinPraison 👋
We discovered 3 security vulnerabilities in PraisonAI related to hardcoded credentials and predictable defaults. Since your SECURITY.md recommends private disclosure, we are opening this issue to ask: what is the best email address to send the full security report to?
We would like to share the complete details (affected files, line numbers, CVSS scores, and fix suggestions) via email for responsible disclosure.
Brief Overview
| # |
Issue |
Severity |
Location |
| 1 |
Hardcoded PostHog API Key in telemetry module |
High (CVSS 8.5) |
praisonaiagents/telemetry/telemetry.py |
| 2 |
Hardcoded WhatsApp verify token in example code |
Medium (CVSS 5.3) |
praisonai_bot/bots/whatsapp.py |
| 3 |
Predictable default JWT secret in platform module |
Medium (CVSS 6.5) |
praisonai_platform/services/jwt_secret.py |
All issues have been verified against the latest code on the main branch.
Request
Could you please provide a security contact email so we can send the full report with reproduction steps and fix suggestions?
Thank you for your time!
Discovered by Correctover — AI Reliability Infrastructure
Summary
Hi @MervinPraison 👋
We discovered 3 security vulnerabilities in PraisonAI related to hardcoded credentials and predictable defaults. Since your SECURITY.md recommends private disclosure, we are opening this issue to ask: what is the best email address to send the full security report to?
We would like to share the complete details (affected files, line numbers, CVSS scores, and fix suggestions) via email for responsible disclosure.
Brief Overview
praisonaiagents/telemetry/telemetry.pypraisonai_bot/bots/whatsapp.pypraisonai_platform/services/jwt_secret.pyAll issues have been verified against the latest code on the
mainbranch.Request
Could you please provide a security contact email so we can send the full report with reproduction steps and fix suggestions?
Thank you for your time!
Discovered by Correctover — AI Reliability Infrastructure