Vulnerability in PraisonAI Multi-Agent System Allows Unauthorized Access
CVE-2026-57123
9.8CRITICAL
What is CVE-2026-57123?
The PraisonAI multi-agent system contains a vulnerability allowing tools to be accessed without proper authentication and validation. Prior to version 1.6.59, the ToolsMCPServer.run_sse and launch_tools_mcp_server methods were improperly bound to 0.0.0.0, exposing critical routes (/sse and /messages/) to any reachable client. This oversight enables potential attackers to list registered tools and even invoke malicious operations, including file modifications and code execution, particularly through DNS rebinding attacks. The issue has been rectified in version 1.6.59, emphasizing the importance of implementing strict security measures and configurations.
Affected Version(s)
praisonaiagents < 1.6.59
