Description
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authentication, origin-validation, or DNS-rebinding controls. Any reachable client can list and invoke registered tools, and a browser can target a local instance through DNS rebinding, with impact determined by the registered file, shell, and code-execution tools. This vulnerability is fixed in praisonaiagents 1.6.59.
Published: 2026-09-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

Prior to praisonaiagents 1.6.59, the ToolsMCPServer.run_sse and launch_tools_mcp_server routines bind to 0.0.0.0 and expose "/sse" and "/messages/" routes without enforcing the available SecurityConfig authentication, origin-validation, or DNS‑rebinding protections. Any client that can reach the host can list and invoke the system’s registered tools, and a browser can target a local instance via DNS rebinding. The impact depends on the nature of the registered file, shell, and code‑execution tools. This flaw enables an attacker to execute arbitrary code or commands, compromising confidentiality, integrity, and availability.

Affected Systems

The flaw affects the praisonaiagents component of PraisonAI, specifically versions prior to 1.6.59. Clients of the distributed multi‑agent system running the vulnerable component can be exploited, regardless of operating system, as long as they can reach the HTTP endpoints on the host.

Risk and Exploitability

The CVSS score of 9.8 marks the vulnerability as critical. The EPSS score is below 1 %, indicating a low but non‑zero probability of exploitation. However, because the MCP SSE transport binds to 0.0.0.0 and omits authentication, origin validation, and DNS‑rebinding protection, any host that can reach the instance—whether within the same network, over the internet, or via DNS rebinding—can exploit the flaw with only network access and no credentials. The attacker can enumerate and invoke the system’s registered tools, including file, shell, and code‑execution tools, granting full compromise of confidentiality, integrity, and availability. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 21, 2026 at 00:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade praisonaiagents to version 1.6.59 or later.
  • Restrict the "/sse" and "/messages/" endpoints to internal networks or block external access using a firewall.
  • Verify that the bundled SecurityConfig is wired in and enforce authentication and origin validation for those endpoints.

Generated by OpenCVE AI on September 21, 2026 at 00:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-x227-pf99-vffg PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in
History

Tue, 15 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonaiagents
Vendors & Products Mervinpraison
Mervinpraison praisonaiagents

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, ToolsMCPServer.run_sse and launch_tools_mcp_server bind to 0.0.0.0 and create /sse and /messages/ routes without invoking the available SecurityConfig authentication, origin-validation, or DNS-rebinding controls. Any reachable client can list and invoke registered tools, and a browser can target a local instance through DNS rebinding, with impact determined by the registered file, shell, and code-execution tools. This vulnerability is fixed in praisonaiagents 1.6.59.
Title PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired in
Weaknesses CWE-1327
CWE-306
CWE-350
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Mervinpraison Praisonaiagents
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:11:47.930Z

Reserved: 2026-06-24T00:33:17.707Z

Link: CVE-2026-57123

cve-icon Vulnrichment

Updated: 2026-09-14T17:11:04.979Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T15:17:05.753

Modified: 2026-09-15T14:45:28.563

Link: CVE-2026-57123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:15:06Z

Weaknesses
  • CWE-1327

    Binding to an Unrestricted IP Address

  • CWE-306

    Missing Authentication for Critical Function

  • CWE-350

    Reliance on Reverse DNS Resolution for a Security-Critical Action