Impact
PraisonAI is a multi‑agent system that, before version 4.6/connect endpoint in its UI host applications without requiring authentication. The request body can contain caller‑controlled commanddioMCPClient, which launches a local process. Because the UI service binds to 0.0.0.0 by default, any reachable client can invoke the endpoint and spawn arbitrary commands under the UI service account regardless of whether the subsequent MCP handshake succeeds. This flaw allows attackers to execute code locally with the privileges of the UI service account, potentially compromising the host system and all data accessible to that user.
Affected Systems
The vulnerability affects the MervinPraison PraisonAI product running any version prior to 4.6.59. The UI host applications of those versions expose the vulnerable endpoint on the default 0.0.0.0 interface.
Risk and Exploitability
The CVSS score of 9.8 places this flaw in the Critical severity range, reflecting a high likelihood of exploitation and severe impact. The EPSS score is < 1%, so the exact probability of exploitation cannot be quantified at this time. The vulnerability is not listed in the CISA KEV catalog. It can be exploited by any external or internal client that can reach the UI host, as the endpoint requires no authentication. Successful exploitation would allow arbitrary code execution under the UI service account.
OpenCVE Enrichment
Github GHSA