Multiple Agent Teams System Vulnerability in PraisonAI by Mervin Praison
CVE-2026-55529

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-55529?

PraisonAI, a system for managing multi-agent teams, has a vulnerability in its HTTP Stream _validate_origin method prior to version 4.6.58. The method incorrectly allows attacker-controlled HTTP origins, such as localhost.evil.example, to pass through the request origin validation mechanism. This flaw enables malicious web pages to send unauthorized requests to the local MCP server without requiring an API key, potentially leading to the execution of exposed tools. The issue was addressed in the latest release, version 4.6.58, which restricts the origin validation to ensure only legitimate requests can access server functionalities.

Affected Version(s)

PraisonAI < 4.6.58

References

CVSS V3.1

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.