Impact
PraisonAI’s MCPServer exposes an unprotected HTTP interface that listens on a network port without restricting the host. Every POST request is forwarded to the internal handleRequest() function without any authentication or authorization checks. A network client that can reach the bound port can invoke the tools/list, tools/call, resources/read, and prompts/get endpoints, causing registered handlers to run with server‑side credentials and process privileges, which allows attackers to execute arbitrary code or disclose sensitive data.
Affected Systems
The vulnerability affects PraisonAI version 1.5.0 through 1.7.2 inclusive, as shipped by MervinPraison. The affected component is the MCPServer.startHttp() routine in src/praisonai-ts/src/mcp/server.ts, which is part of the PraisonAI multi‑agent system.
Risk and Exploitability
The CVSS score of 9.8 marks the flaw as critical, and although the EPSS score is less than 1%, the lack of authentication or authorization means any network client that can reach the bound port can exploit the flaw. The vulnerability is not listed in the CISA KEV catalog, but the severity and the open‑to‑any‑client nature of the service make it a high‑risk exposure for organizations that host PraisonAI services.
OpenCVE Enrichment
Github GHSA