Junglewise Threat Intelligence

CVE-2026-57123: PraisonAI Tools MCP Server authentication bypass

CVE-2026-57123 · Severity: critical · CVSS 9.8 · Published 2026-09-14

Technologies: praisonaiagents (PyPI). Vendors: PyPI, PraisonAI.

Executive brief

PraisonAI is a multi-agent framework that orchestrates autonomous AI teams to accomplish complex tasks. The ToolsMCPServer component fails to enforce authentication controls on its API endpoints, allowing any network-reachable client to discover and execute registered tools (including file operations, shell commands, and code execution) without authorization. A malicious user or malware can exploit this to gain complete system access and control.

Technical details

The vulnerability is an authentication bypass in PraisonAI's ToolsMCPServer, specifically in the run_sse() and launch_tools_mcp_server() functions, which bind to 0.0.0.0 and expose /sse and /messages/ endpoints without enforcing available SecurityConfig authentication, origin-validation, or DNS-rebinding protections. Any client with network access can invoke the endpoints to list and trigger registered tools. The scope of damage is determined by which tools are registered—this can include arbitrary file read/write, shell command execution, and code evaluation. DNS rebinding attacks from a browser can bypass localhost isolation. The vulnerability was patched in praisonaiagents version 1.6.59 and later.

Affected products

  • PraisonAI praisonaiagents before 1.6.59

Timeline

  • 2026-09-14: disclosed
  • 2026-06-13: patched: Fix committed; version 1.6.59 released

References

Related threats