{"id":"CVE-2026-57123","title":"PraisonAI is a multi-agent teams system","summary":"PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authenticati…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-306","CWE-350","CWE-1327"],"vendor":"MervinPraison","product":"praisonaiagents","affected":["praisonaiagents < 1.6.59"],"patched":["praisonaiagents 1.6.59"],"published":"2026-09-14","updated":"2026-09-15","sourceUpdated":"2026-09-15T14:45:28.563","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-57123","references":[{"url":"https://github.com/MervinPraison/PraisonAI/commit/2adfe7e8323f6deec66925cf15a885b6238895e9","label":"security-advisories@github.com"},{"url":"https://github.com/MervinPraison/PraisonAI/releases/tag/v4.6.59","label":"security-advisories@github.com"},{"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-x227-pf99-vffg","label":"security-advisories@github.com"},{"url":"https://github.com/MervinPraison/PraisonAI"}],"tags":["nvd","cve.org","osv","pip"],"epss":0.00474,"epssPercentile":0.40049,"aliases":["GHSA-x227-pf99-vffg"],"ecosystem":"pip","ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-09-14T17:11:03.797818Z"},"ingestedAt":"2026-07-21T19:04:57.836Z","slug":"CVE-2026-57123","body":"## Overview\n\nPraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authentication, origin-validation, or DNS-rebinding controls. Any reachable client can list and invoke registered tools, and a browser can target a local instance through DNS rebinding, with impact determined by the registered file, shell, and code-execution tools. This vulnerability is fixed in praisonaiagents 1.6.59.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-57123)\n\nAffected packages:\n\n- `praisonaiagents < 1.6.59`\n\nPatched in:\n\n- `praisonaiagents 1.6.59`\n\nSource: https://osv.dev/vulnerability/GHSA-x227-pf99-vffg","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}