PT-2026-108715 · Pypi · Praisonai
CVE-2026-62178
·
Publicado
2026-10-08
·
Atualizado
2026-10-08
CVSS v3.1
7.3
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Summary
PraisonAI's MCP HTTP-stream server authenticates requests only when an API key is configured; the CLI defaults
--api-key to None, so praisonai mcp serve --transport http-stream exposes the full MCP surface unauthenticated. A request with no Authorization (and no Origin) can initialize and tools/list (~50 tools), and the dispatcher forwards tool-call arguments to handlers without validating them against the advertised inputSchema. Runtime-confirmed for unauthenticated initialize/tools/list and the dispatcher schema-bypass. This is not an RCE/file-read in 4.6.63 — workflow.run/workflow.run file are runtime-refuted (adapter regression). Severity Medium–High.Details
Affected component
- Package:
praisonai4.6.63. Files:src/praisonai/praisonai/mcp server/transports/http stream.py,mcp server/cli.py,mcp server/server.py(dispatcher).
Vulnerable code / root cause
Path:
src/praisonai/praisonai/mcp server/transports/http stream.pyFunction:
mcp post / validate originSnippet:
python
if self.api key: # auth applied ONLY when api key is set
auth header = request.headers.get("Authorization", "")
if not auth header.startswith("Bearer ") or auth header[7:] != self.api key:
return JSONResponse({"error": "Unauthorized"}, status code=401)
# validate origin: returns True when the Origin header is absentIssue: with
api key=None, no auth check runs; a missing Origin header is allowed, so non-browser clients (curl/Burp) are not blocked.Path:
src/praisonai/praisonai/mcp server/cli.pyFunction:
cmd serve (argparse)Snippet:
python
parser.add argument("--api-key", default=None) # unauthenticated by defaultPath:
src/praisonai/praisonai/mcp server/server.pyFunction:
handle tools callSnippet:
python
result = await tool.handler(**arguments) # arguments forwarded without inputSchema validationIssue: attacker-controlled
arguments are passed straight to the handler; the dispatcher does not validate them against the tool's advertised inputSchema. The only thing rejecting undeclared keys is the handler's own Python signature.Attack flow
- Operator runs
praisonai mcp serve --transport http-stream(no--api-key). - Attacker (no auth, no Origin) sends
initialize→ session;tools/list→ enumerates ~50 tools;tools/call→ arguments pass through unvalidated.
Why existing protection is bypassed
Auth is opt-in (only added when an api key is set); missing
Origin is allowed; the dispatcher does not enforce inputSchema.Security boundary
Unauthenticated access to the MCP tool surface. Default bind
127.0.0.1 (any local process / multi-user host; remote only if --host 0.0.0.0).Scope limits (do not overclaim)
praisonai.workflow.run/workflow.run fileare runtime-refuted in 4.6.63: the adapter callsAgentsGenerator(...)missing the requiredconfig listargument → errors before any execution/file open. Several other tool adapters also error at runtime. No unauthenticated RCE/arbitrary-file-open via these tools at HEAD.- MCP
knowledge.addfile read is broken (seeFT-01 Knowledge FileRead Negative Report.md).
Proof of Concept
Environment
Real MCP HTTP-stream server (
api key=None) in a local runtime (127.0.0.1:18090). Runnable assets: PraisonAI-Runtime-Reproruntime-files (docker-compose.mcp.yml). MCP requests use Accept: application/json + header Mcp-Session-Id.Steps to reproduce
MCP-Initialize:POST /mcpinitialize (no Authorization) →200+mcp-session-id.MCP-Tools-List-NoAuth:POST /mcptools/listwith that session id →200+ ~50 tools.MCP-Schema-Bypass:tools/callwith an undeclared extra argument (undeclared evil param).
Expected result
The transport requires authentication; the dispatcher validates arguments against
inputSchema.Actual result
initialize/tools/listsucceed with no auth and no Origin header.- The undeclared argument reaches the handler (
got an unexpected keyword argument ' undeclared evil param '), proving no schema validation at the dispatcher.
Screenshots
Screenshots
Unauthenticated MCP initialize
A POST request to
/mcp with method initialize succeeds without an Authorization header. The server returns HTTP 200 OK, exposes MCP capabilities, and issues an mcp-session-id to the unauthenticated client.Unauthenticated MCP tools/list
After initialization, the same unauthenticated MCP session can call
tools/list using only the issued Mcp-Session-Id. The server returns HTTP 200 OK and exposes tool names, schemas, and annotations.MCP tool-call schema bypass
The unauthenticated MCP client calls
tools/call with an extra argument not declared in the tool schema. Instead of rejecting the schema-violating input at the dispatcher layer, the unexpected parameter reaches the Python handler and causes an unexpected keyword argument error. This confirms incomplete input-schema enforcement for tool calls.Impact
Unauthenticated tool enumeration and tool-call surface; LLM-key/cost abuse and data access via whichever tools function (impact currently limited by several broken adapters and the default loopback bind). No confirmed unauthenticated RCE/file-read in 4.6.63.
Correção
Missing Authorization
Missing Authentication
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Praisonai