Junglewise Threat Intelligence

PraisonAI ToolsMCPServer DNS rebinding in legacy SSE transport

Severity: high · CVSS 8.3 · Published 2026-06-18

Vendors: MervinPraison.

Executive brief

PraisonAI is an AI agent framework that allows users to expose tools (like file access or API integrations) via a local server. A security flaw in its legacy SSE transport mode allows malicious websites to bypass security checks and interact with these tools if a user visits a compromised site. This could allow an attacker to read private files, modify data, or execute commands on the user's local machine through the exposed AI tools.

Technical details

The `ToolsMCPServer.run_sse()` function in PraisonAI constructs a Starlette application using `SseServerTransport` without implementing middleware or route-level checks for 'Origin', 'Host', or 'Authorization' headers. This vulnerability allows a remote attacker to perform a DNS rebinding attack. When a victim visits a malicious website, the attacker can send requests to the victim's local or internal PraisonAI SSE MCP server. Because the server lacks validation, the attacker can discover and invoke registered tools, potentially leading to arbitrary code execution or data exfiltration depending on the tools' capabilities. This issue specifically affects the legacy SSE transport path, whereas the Streamable HTTP transport correctly enforces these guards.

Affected products

  • MervinPraison praisonaiagents >= 0.6.0, <= 1.6.58
  • MervinPraison praisonai >= 3.10.0, <= 4.6.58

Timeline

  • 2026-06-17: disclosed: Initial disclosure on GitHub Advisories
  • 2026-06-18: advisory: Advisory published
  • 2026-06-18: patched: Fixed in praisonai 4.6.59 and praisonaiagents 1.6.59

References