CVE-2026-57112High· 8.3▾ MidnightPoC availablePraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents/mcp/mcp_server.py mounts SseServerTransport on the legac…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 45.7 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
0.2% → 0.2%
Exploit / PoC code exists
PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents/mcp/mcp_server.py mounts SseServerTransport on the legacy /sse and /messages/ endpoints without default Host, Origin, or authentication enforcement. A malicious website can use DNS rebinding against a reachable local or internal SSE server, supply attacker-controlled Host and Origin headers, enumerate registered tools, and invoke them with the server user's privileges. The Streamable HTTP transport rejects the same hostile Origin, which isolates the flaw to the legacy SSE wrapper. An initial remediation was released in praisonaiagents 1.6.59 and PraisonAI 4.6.59.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
praisonaiagents >= 0.6.0, < 1.6.59praisonai >= 3.10.0, < 4.6.59Patched in:
praisonaiagents 1.6.59praisonai 4.6.59Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-57124Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-57125Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-57119High· 7.5PraisonAI is a multi-agent teams system
CVE-2026-57131Critical· 9.8PraisonAI is a multi-agent teams system
CVE-2026-57122High· 8.6PraisonAI is a multi-agent teams system
CVE-2026-57123Critical· 9.8PraisonAI is a multi-agent teams system