praisonai-platform PyPI Package: Potential Hardcoded JWT Secret Issue
An early warning has been issued regarding the praisonai-platform package on PyPI, versions <= 0.1.4, which reportedly uses a hardcoded JWT secret, potentially allowing unauthenticated attackers to bypass authentication.
What happened
The praisonai-platform package, versions up to and including 0.1.4, appears to initialize with a hardcoded JWT secret 'dev-secret-change-me'. This default-open production guard may lead to insecure default initialization and use of hard-coded credentials. As a result, unauthenticated attackers could potentially bypass authentication mechanisms.
This issue is currently under investigation, with tracked IDs GHSA-3QG8-5G3R-79V5 and GHSA-F38V-77QJ-H4JQ. It is recommended that users upgrade to a version of praisonai-platform that properly enforces the production guard and does not use a hardcoded JWT secret. Additionally, ensure that PLATFORM_JWT_SECRET is explicitly set in any deployment to mitigate potential risks.
For more detailed information, consult the primary sources linked in the threat data. The severity of this issue is classified as HIGH, and it is advised to take immediate action to assess and mitigate exposure.
How 0Day mitigates this
praisonai-platform is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.