CVE-2026-47410
CRITICAL SEVERITYCVSS Score & Metrics
Base Score
9.8 / 10
Vulnerability Description
praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset
Vulnerability Details
Published Date
Last Modified
Source
GitHub
Vendor
pip
Product
praisonai-platform
Discussion (0)
Add Comment
No comments yet. Be the first!