CVE-2026-55529: PraisonAI Origin Validation Bypass
PraisonAI versions prior to 4.6.58 contain an origin validation bypass in the MCP HTTP Stream _validate_origin method that allows attackers to submit tool execution requests to local MCP servers without API key authentication through malicious webpages.
Disclosed 25 August 2026 · Record updated 13 September 2026
Impact
Attackers could execute exposed tools on local MCP servers without authentication by exploiting the origin validation bypass.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55529
