HighVulnerability
GHSA-hc5v-gxvj-58wh: PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface
- Identifiers
- CVE-2026-61427GHSA-hc5v-gxvj-58wh
- Published
- Record updated
Summary
PraisonAI 4.6.63's MCP HTTP-stream server applies authentication only when an API key is set, and the CLI defaults `--api-key` to `None`, so `praisonai mcp serve --transport http-stream` exposes the full MCP surface without authentication. An unauthenticated client can call `initialize` and `tools/list` (about 50 tools), and the dispatcher in `mcp_server/server.py` forwards tool-call arguments to handlers without validating them against the advertised `inputSchema`. The source states this is not an RCE or file read in 4.6.63, because `workflow.run` and `workflow.run_file` fail at runtime.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Topics
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database