CRITICAL
9.8 CVE-2026-57139 Published 15 Sept 2026
PraisonAI Unauthenticated HTTP Request Handling Bug
Worried this affects one of your servers?
PraisonAI, a multi-agent teams system, is affected by a vulnerability in its HTTP request handling mechanism.
From version 1.5.0 to 1.7.2, the MCPServer.startHttp() function in src/praisonai-ts/src/mcp/server.ts binds without a host restriction, allowing any network client to reach the port and call certain endpoints without authentication or authorization.
This can lead to registered handlers running with server-side credentials and process privileges or disclose registered data.
An initial remediation was released in version 1.7.2.
Reference: CVE-2026-57139 on NVD
← Back to Security News