CVE-2026-61427

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option defaults to None, and the server only enforces Authorization/Bearer checks when an API key is configured. When an operator runs 'praisonai mcp serve --transport http-stream' without an API key, an unauthenticated client (no Authorization header, and no Origin header, which is also permitted) can initialize a session, enumerate the available tools (tools/list), and invoke tools (tools/call). Additionally, the dispatcher forwards tool-call arguments to handlers without validating them against the advertised inputSchema. The server binds to 127.0.0.1 by default, so remote exploitation requires the operator to bind to a network-accessible address (e.g., --host 0.0.0.0).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-10: 110-10
Referenced assets6 URLs
Full discourse1 post
  • Code Solutions@CodeSolutionsIL

    Don’t Panic Digest Inform. Gate. Then automate. News — PraisonAI security advisories (GitHub, Oct 8): PraisonAI, an open-source framework for building SI (super intelligence) agents, published three advisories rated high to critical (CVE-2026-61426, CVSS 8.6; CVE-2026-61427, 7.3; CVE-2026-61445, 9.9). In its default setup, the agent server could be reached by anyone on the network with no login, and the tool-server mode had no login unless a key was set. A third flaw let a model’s tool calls write files and run commands without checks, so a prompt injection could lead to command execution. The advisories list fixes in releases 1.7.3 and 4.6.78, and newer releases are out. Not in CISA KEV; none of the sources we read reports exploitation. Operator read: upgrade, require a login before an agent server starts, keep it on a trusted network, and give a model’s tool calls only the file and command access a person has approved. https://github.com/advisories/GHSA-9mp3-24cc-77mg Related: UK AISI’s “Transect: Making large-scale agentic evaluations easier to understand” (Oct 7) — AISI says a final score reveals little of how a long agent run went; Transect, an open-source tool, lays the agent’s recorded steps out as one timeline, and AISI warns that SI-made labels “can be wrong or misleading”. For us, judge an agent by its record, and spot-check any SI summary of it. Our Plainwrap daily notes: https://x.com/CodeSolutionsIL/status/2108588340413100309 https://www.aisi.gov.uk/blog/transect-making-large-scale-agentic-evaluations-easier-to-understand More — Matt Turck × Andy Pavlo (agents and databases, ~04:09–10:51 + 15:10–30:43): What’s in it: Matt Turck and database researcher Andy Pavlo talk about what happens when SI agents get access to databases: copies (branches) for safe testing, agents that delete data, and why Pavlo says the old permission controls should apply to agents too. They also cover where agent memory should live and how well agents turn plain questions into database queries, with Pavlo’s numbers given as his own account. Our takeaway: Give agents the same scoped permissions you would give a person, let them test on a separate copy, and keep a named person’s OK on anything destructive. Notes of a public podcast; the speakers’ claims are as discussed, not verified. https://gist.github.com/CodeSolutionsLLC/6cc37a8e83a82d4689a3a3cd4b9f5319 https://x.com/mattturck/status/2108223135673696504 https://codesolutionsllc.com/news

    1000069
    12 followersView on X

Explore more