Description
PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth policies accept any non-empty Authorization header without calling auth.validate(), then return an authenticated result, allowing callers with invalid credentials to access MCP tools and resources protected by those policies. This issue is fixed in version 1.7.2.
Published: 2026-09-15
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass
Action: Patch Immediately
AI Analysis

Impact

From versions 1.5.1 to 1.7.2, MCPSecurity.evaluatePolicy() calls the credential validator only for api‑key or bearer methods. For Basic and OAuth, the validator is accepted and the function returns an authenticated result, granting access to MCP tools and resources that the policy protects. As a consequence, callers with invalid credentials can authenticate and compromise protected resources. The flaw exemplifies Improper Authentication (CWE‑287), Improper Authorization (CWE‑288), and Improper Authorization Enforcement (CWE‑863). The issue has been resolved in version 1.7.2.

Affected Systems

The vulnerability affects MervinPraison PraisonAI versions 1.5.1 through 1.7.2 inclusive. Users of any release in that range are impacted and should upgrade to 1.7.2 or later.

Risk and Exploitability

With a CVSS score of 8.2 the flaw is high severity. The EPSS score of less than exploitation, yet the attack is trivial: any external actor can send an HTTP request with an arbitrary Authorization header to bypass authentication. The vulnerability is not yet in CISA’s KEV catalog, but its ease of exploitation could lead to future exploitation and potential data exposure or unauthorized control of protected resources.

Generated by OpenCVE AI on September 17, 2026 at 17:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PraisonAI to version 1.7.2 or a newer release to apply the official fix.
  • Re‑enable credential validation for Basic and OAuth policies or disable those authentication methods if they are not required.
  • Conduct a review of exposed APIs to confirm no other endpoints rely on Basic/OAuth without validation and monitor traffic for anomalous Authorization header usage.

Generated by OpenCVE AI on September 17, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4qq2-2j2x-x62c npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Tue, 15 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth policies accept any non-empty Authorization header without calling auth.validate(), then return an authenticated result, allowing callers with invalid credentials to access MCP tools and resources protected by those policies. This issue is fixed in version 1.7.2.
Title PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
Weaknesses CWE-287
CWE-288
CWE-863
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T12:37:03.514Z

Reserved: 2026-06-24T00:33:17.708Z

Link: CVE-2026-57134

cve-icon Vulnrichment

Updated: 2026-09-15T12:36:51.657Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:10.583

Modified: 2026-09-15T14:45:28.563

Link: CVE-2026-57134

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel

  • CWE-863

    Incorrect Authorization