Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-55529: PraisonAI Origin Validation Bypass

PraisonAI versions prior to 4.6.58 contain an origin validation bypass in the MCP HTTP Stream _validate_origin method that allows attackers to submit tool execution requests to local MCP servers without API key authentication through malicious webpages.

Disclosed 25 August 2026 · Record updated 13 September 2026

Impact

Attackers could execute exposed tools on local MCP servers without authentication by exploiting the origin validation bypass.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55529