GHSA-pvph-5j39-v8qc: PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
Summary
PraisonAI's HTTP server has a flaw in how it checks which websites are allowed to make requests to it, using a prefix match that allows attackers to bypass it by registering domains like 'localhost.attacker.com'. Combined with no default authentication and no requirement for session validation, an attacker can trick a victim into visiting a malicious webpage that silently makes requests to the victim's local PraisonAI server to create rules that inject the attacker's instructions into all future agent runs on that machine.
Vulnerability Details
EPSS: 0.0%
Yes
August 25, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://github.com/advisories/GHSA-pvph-5j39-v8qc
First tracked: August 25, 2026 at 02:01 PM
Classified by LLM (prompt v3) · confidence: 92%