Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-57139: PraisonAI MCPServer lets anyone run tools via HTTP
CVE-2026-57139 · published 25 days ago
Summary
Versions 1.5.0 through 1.7.1 of PraisonAI’s MCPServer accept HTTP requests without checking who is calling. Any computer that can reach the server’s port can trigger actions, read data, or run commands using the server’s own privileges. Upgrade to version 1.7.2 or later, or block external access to the port, to stop the issue.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| mervinpraison | praisonai | >= 1.5.0, < 1.7.2 |
Original advisory text
PraisonAI MCPServer exposes unauthenticated HTTP tools/call
PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/server.ts binds without a host restriction and forwards every HTTP POST request to handleRequest() without authentication or authorization. Any network client that can reach the port can call tools/list, tools/call, resources/read, or prompts/get, causing registered handlers to run with server-side credentials and process privileges or disclose registered data. An initial remediation was released in version 1.7.2.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-306Missing Authentication for Critical Function
CWE-862Missing Authorization
CWE-1188Initialization of a Resource with an Insecure Default
Timeline
Published15 Sep 2026
Updated7 Oct 2026
First seen15 Sep 2026
Track software like this
Free during beta