CRITICAL 9.8 CVE-2026-57139 Published 15 Sept 2026

PraisonAI Unauthenticated HTTP Request Handling Bug

Worried this affects one of your servers?

PraisonAI, a multi-agent teams system, is affected by a vulnerability in its HTTP request handling mechanism.

From version 1.5.0 to 1.7.2, the MCPServer.startHttp() function in src/praisonai-ts/src/mcp/server.ts binds without a host restriction, allowing any network client to reach the port and call certain endpoints without authentication or authorization.

This can lead to registered handlers running with server-side credentials and process privileges or disclose registered data.

An initial remediation was released in version 1.7.2.

Reference: CVE-2026-57139 on NVD

← Back to Security News