CVE-2026-61427: Authentication Bypass and Unvalidated Tool Execution in PraisonAI MCP HTTP-Stream Server
Vulnerability ID: CVE-2026-61427
CVSS Score: 7.3
Published: 2026-10-08
CVE-2026-61427 is a critical authentication bypass and improper input validation vulnerability within the Model Context Protocol (MCP) HTTP-stream server of PraisonAI. In versions prior to 4.6.78, the server lacks authentication by default and forwards client messages directly to Python tool handlers without input validation. When bound to non-localhost interfaces, this permits unauthenticated remote attackers to perform unauthorized administrative operations and execute tools.
TL;DR
Unauthenticated remote attackers can query and invoke administrative tools on PraisonAI MCP servers due to missing default authentication and input validation.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-306 (Missing Authentication), CWE-20 (Improper Input Validation)
- Attack Vector: Network
- CVSS v3.1: 7.3 (High)
- EPSS Score: 0.00389 (~0.39% probability)
- Exploit Status: Proof of Concept (PoC)
- CISA KEV Status: Not Listed
Affected Systems
- PraisonAI MCP Server Component
-
PraisonAI: < 4.6.78 (Fixed in:
4.6.78)
Code Analysis
Commit: 393de39
Fix: Require api_key when MCP HTTP-stream binds to a non-localhost address
Mitigation Strategies
- Upgrade PraisonAI to version 4.6.78 or above.
- Explicitly configure an API key when launching the MCP HTTP-stream server.
- Restrict bind interfaces to localhost (127.0.0.1) unless external connectivity is required.
- Implement firewall rules to drop traffic on port 8000 from untrusted IP ranges.
Remediation Steps:
- Execute pip install --upgrade praisonai to apply the fix.
- Verify the version using pip show praisonai.
- Modify execution scripts to generate and pass a strong API key via the --api-key argument.
- Restrict host bindings by using --host 127.0.0.1.
References
Read the full report for CVE-2026-61427 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)