PYPI · JUNE 2026 · EARLY WARNING

praisonai-platform PyPI Package: Potential Hardcoded JWT Secret Issue

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-3QG8-5G3R-79V5GHSA-F38V-77QJ-H4JQSeverity: HIGH

An early warning has been issued regarding the praisonai-platform package on PyPI, versions <= 0.1.4, which reportedly uses a hardcoded JWT secret, potentially allowing unauthenticated attackers to bypass authentication.

What happened

The praisonai-platform package, versions up to and including 0.1.4, appears to initialize with a hardcoded JWT secret 'dev-secret-change-me'. This default-open production guard may lead to insecure default initialization and use of hard-coded credentials. As a result, unauthenticated attackers could potentially bypass authentication mechanisms.

This issue is currently under investigation, with tracked IDs GHSA-3QG8-5G3R-79V5 and GHSA-F38V-77QJ-H4JQ. It is recommended that users upgrade to a version of praisonai-platform that properly enforces the production guard and does not use a hardcoded JWT secret. Additionally, ensure that PLATFORM_JWT_SECRET is explicitly set in any deployment to mitigate potential risks.

For more detailed information, consult the primary sources linked in the threat data. The severity of this issue is classified as HIGH, and it is advised to take immediate action to assess and mitigate exposure.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If praisonai-platform is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats