A vulnerability was found in MervinPraison PraisonAI up to 4.6.39. It has been declared as critical. Affected by this vulnerability is the function verify_token of the file praisonai/api/call.py of the component praisonai.api.agent_invoke. Executing a manipulation of the argument CALL_SERVER_TOKEN can lead to improper authentication.

The identification of this vulnerability is CVE-2026-47396. The attack may be launched remotely. There is no exploit available.