GHSA-5866-9272-qcfvMedium· 7.3▾ SunlitDuplicate Advisory: PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface
▾ Sunlit zone — Low / medium · no exploitation signal
impact 40.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-hc5v-gxvj-58wh. This link is maintained to preserve external references.
PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option defaults to None, and the server only enforces Authorization/Bearer checks when an API key is configured. When an operator runs 'praisonai mcp serve --transport http-stream' without an API key, an unauthenticated client (no Authorization header, and no Origin header, which is also permitted) can initialize a session, enumerate the available tools (tools/list), and invoke tools (tools/call). Additionally, the dispatcher forwards tool-call arguments to handlers without validating them against the advertised inputSchema. The server binds to 127.0.0.1 by default, so remote exploitation requires the operator to bind to a network-accessible address (e.g., --host 0.0.0.0).
praisonai <= 4.6.77Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61427High· 7.3PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface
GHSA-3wrm-pm5v-8vq8Medium· 7.2Duplicate Advisory: PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF
CVE-2026-60091High· 7.2PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF
GHSA-65c8-r727-2mpjHigh· 7.5Duplicate Advisory: PraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend
CVE-2026-60085HighPraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend
GHSA-wj29-gm8v-33x8Critical· 9.9Duplicate Advisory: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls