Vulnerability in PraisonAI Multi-Agent System Allows Unauthorized Access
CVE-2026-57123

9.8CRITICAL

Key Information:

Vendor
CVE Published:
14 September 2026

What is CVE-2026-57123?

The PraisonAI multi-agent system contains a vulnerability allowing tools to be accessed without proper authentication and validation. Prior to version 1.6.59, the ToolsMCPServer.run_sse and launch_tools_mcp_server methods were improperly bound to 0.0.0.0, exposing critical routes (/sse and /messages/) to any reachable client. This oversight enables potential attackers to list registered tools and even invoke malicious operations, including file modifications and code execution, particularly through DNS rebinding attacks. The issue has been rectified in version 1.6.59, emphasizing the importance of implementing strict security measures and configurations.

Affected Version(s)

praisonaiagents < 1.6.59

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.