Disclosure summary
## Summary PraisonAI's MCP HTTP-stream server authenticates requests only when an API key is configured; the CLI defaults `--api-key` to `None`, so `praisonai mcp serve --transport http-stream` exposes the full MCP surface unauthenticated. A request with no `Authorization` (and no `Origin`) can `initialize` and `tools/list` (~50 tools), and the dispatcher forwards tool-call arguments to handlers without validating them against the advertised `inputSchema`. Runtime-confirmed for unauthenticated `initialize`/`tools/list` and the dispatcher schema-bypass. This is **not** an RCE/file-read in 4.6.63 — `workflow.run`/`workflow.run_file` are runtime-refuted (adapter regression). Severity Medium–High. ## Details ### Affected component - Package: `praisonai` 4.6.63. Files: `src/praisonai/praisonai/mcp_server/transports/http_stream.py`, `mcp_server/cli.py`, `mcp_server/server.py` (dispatcher). ### Vulnerable code / root cause Path: `src/praisonai/praisonai/mcp_server/transports/http_stream.py` Function: `mcp_post` / `_validate_origin` Snippet: ```python if self.api_key: # auth applied ONLY when api_key is set auth_header = request.headers.get("Authorization", "") if not auth_header.startswit
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-hc5v-gxvj-58wh
Open original source · Updated Oct 08, 2026
PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | praisonai | 4.6.78 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-08T17:58:42-04:00
MODIFIED 2026-10-08T17:58:46-04:00
INGESTED 2026-10-10T20:25:14-04:00