Impact
Prior to praisonaiagents 1.6.59, the ToolsMCPServer.run_sse and launch_tools_mcp_server routines bind to 0.0.0.0 and expose "/sse" and "/messages/" routes without enforcing the available SecurityConfig authentication, origin-validation, or DNS‑rebinding protections. Any client that can reach the host can list and invoke the system’s registered tools, and a browser can target a local instance via DNS rebinding. The impact depends on the nature of the registered file, shell, and code‑execution tools. This flaw enables an attacker to execute arbitrary code or commands, compromising confidentiality, integrity, and availability.
Affected Systems
The flaw affects the praisonaiagents component of PraisonAI, specifically versions prior to 1.6.59. Clients of the distributed multi‑agent system running the vulnerable component can be exploited, regardless of operating system, as long as they can reach the HTTP endpoints on the host.
Risk and Exploitability
The CVSS score of 9.8 marks the vulnerability as critical. The EPSS score is below 1 %, indicating a low but non‑zero probability of exploitation. However, because the MCP SSE transport binds to 0.0.0.0 and omits authentication, origin validation, and DNS‑rebinding protection, any host that can reach the instance—whether within the same network, over the internet, or via DNS rebinding—can exploit the flaw with only network access and no credentials. The attacker can enumerate and invoke the system’s registered tools, including file, shell, and code‑execution tools, granting full compromise of confidentiality, integrity, and availability. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Github GHSA