Impact
From versions 1.5.1 to 1.7.2, MCPSecurity.evaluatePolicy() calls the credential validator only for api‑key or bearer methods. For Basic and OAuth, the validator is accepted and the function returns an authenticated result, granting access to MCP tools and resources that the policy protects. As a consequence, callers with invalid credentials can authenticate and compromise protected resources. The flaw exemplifies Improper Authentication (CWE‑287), Improper Authorization (CWE‑288), and Improper Authorization Enforcement (CWE‑863). The issue has been resolved in version 1.7.2.
Affected Systems
The vulnerability affects MervinPraison PraisonAI versions 1.5.1 through 1.7.2 inclusive. Users of any release in that range are impacted and should upgrade to 1.7.2 or later.
Risk and Exploitability
With a CVSS score of 8.2 the flaw is high severity. The EPSS score of less than exploitation, yet the attack is trivial: any external actor can send an HTTP request with an arbitrary Authorization header to bypass authentication. The vulnerability is not yet in CISA’s KEV catalog, but its ease of exploitation could lead to future exploitation and potential data exposure or unauthorized control of protected resources.
OpenCVE Enrichment
Github GHSA