Multiple Agent Teams System Vulnerability in PraisonAI by Mervin Praison
CVE-2026-55529
6.9MEDIUM
What is CVE-2026-55529?
PraisonAI, a system for managing multi-agent teams, has a vulnerability in its HTTP Stream _validate_origin method prior to version 4.6.58. The method incorrectly allows attacker-controlled HTTP origins, such as localhost.evil.example, to pass through the request origin validation mechanism. This flaw enables malicious web pages to send unauthorized requests to the local MCP server without requiring an API key, potentially leading to the execution of exposed tools. The issue was addressed in the latest release, version 4.6.58, which restricts the origin validation to ensure only legitimate requests can access server functionalities.
Affected Version(s)
PraisonAI < 4.6.58
