CVE-2026-61427: Improper Input Validation in MervinPraison PraisonAI
PraisonAI versions before 4.6.78 have a vulnerability where the MCP HTTP-stream transport is exposed without authentication by default. The CLI option for API key defaults to None, so unless an API key is explicitly configured, unauthenticated clients can initialize sessions, enumerate available tools, and invoke them. Input arguments to tool calls are not validated against the advertised input schema. The server binds to localhost by default, so remote exploitation requires binding to a network-accessible address.
AI Analysis
Technical Summary
CVE-2026-61427 describes an improper input validation and authentication bypass vulnerability in MervinPraison's PraisonAI prior to version 4.6.78. The MCP HTTP-stream transport interface is exposed without authentication by default because the CLI --api-key option defaults to None. Without an API key configured, the server does not enforce Authorization/Bearer token checks, allowing unauthenticated clients to initialize sessions, list available tools, and invoke tools. Additionally, the dispatcher forwards tool-call arguments to handlers without validating them against the input schema, potentially allowing malformed or unexpected input. The server binds to 127.0.0.1 by default, limiting remote exploitation unless the operator explicitly binds to a network-accessible interface such as 0.0.0.0.
Potential Impact
An unauthenticated attacker on a network-accessible interface can interact with the PraisonAI MCP HTTP-stream transport to enumerate and invoke tools without authorization. Improper input validation may allow malformed inputs to reach tool handlers, potentially leading to unintended behavior or further exploitation. However, by default, the server binds only to localhost, limiting exposure to local users unless configured otherwise.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Operators should ensure that the server is not bound to network-accessible addresses unless necessary. Configuring an API key with the --api-key option will enforce Authorization/Bearer token checks and prevent unauthenticated access. Until an official fix is available, avoid running the MCP HTTP-stream transport without authentication and avoid binding to 0.0.0.0 or other public interfaces.
CVE-2026-61427: Improper Input Validation in MervinPraison PraisonAI
Description
PraisonAI versions before 4.6.78 have a vulnerability where the MCP HTTP-stream transport is exposed without authentication by default. The CLI option for API key defaults to None, so unless an API key is explicitly configured, unauthenticated clients can initialize sessions, enumerate available tools, and invoke them. Input arguments to tool calls are not validated against the advertised input schema. The server binds to localhost by default, so remote exploitation requires binding to a network-accessible address.
CVSS v4.0
Score 6.9medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-61427 describes an improper input validation and authentication bypass vulnerability in MervinPraison's PraisonAI prior to version 4.6.78. The MCP HTTP-stream transport interface is exposed without authentication by default because the CLI --api-key option defaults to None. Without an API key configured, the server does not enforce Authorization/Bearer token checks, allowing unauthenticated clients to initialize sessions, list available tools, and invoke tools. Additionally, the dispatcher forwards tool-call arguments to handlers without validating them against the input schema, potentially allowing malformed or unexpected input. The server binds to 127.0.0.1 by default, limiting remote exploitation unless the operator explicitly binds to a network-accessible interface such as 0.0.0.0.
Potential Impact
An unauthenticated attacker on a network-accessible interface can interact with the PraisonAI MCP HTTP-stream transport to enumerate and invoke tools without authorization. Improper input validation may allow malformed inputs to reach tool handlers, potentially leading to unintended behavior or further exploitation. However, by default, the server binds only to localhost, limiting exposure to local users unless configured otherwise.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Operators should ensure that the server is not bound to network-accessible addresses unless necessary. Configuring an API key with the --api-key option will enforce Authorization/Bearer token checks and prevent unauthenticated access. Until an official fix is available, avoid running the MCP HTTP-stream transport without authentication and avoid binding to 0.0.0.0 or other public interfaces.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-09T14:05:21.470Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a57771e68715ace43a93b81
Added to database: 07/15/2026, 12:03:42 UTC
Last enriched: 07/22/2026, 22:59:56 UTC
Last updated: 08/28/2026, 22:52:12 UTC
Views: 53
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.