top of page
perceptive_background_267k.jpg

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses request_origin.startswith(allowed), allowing the attac…

Published:

25 augustus 2026 om 00:00:00

Alert date:

25 augustus 2026 om 19:07:30

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Emerging Technologies, Identity & Access

CVE-2026-55532 affects PraisonAI, a multi-agent teams system, in versions prior to 4.6.58. The vulnerability exists in the MCP HTTP Stream _validate_origin function, which uses a startswith() check to validate request origins against an allowlist. An attacker can craft a malicious origin such as localhost.attacker.com that satisfies the localhost allowlist check due to the flawed string prefix matching. This allows cross-origin requests to be sent without CORS preflight by using Content-Type: text/plain, enabling unauthenticated access to the tools/call API endpoint without an API key. Successful exploitation can lead to unauthorized file writes that persist malicious agent instructions, potentially compromising the integrity of AI agent behavior. The vulnerability has been patched in PraisonAI version 4.6.58.

Technical details

Mitigation steps:

Affected products:

PraisonAI

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page