


Perceptive Security
SOC/SIEM Consultancy

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses request_origin.startswith(allowed), allowing the attac…
Published:
25 augustus 2026 om 00:00:00
Alert date:
25 augustus 2026 om 19:07:30
Source:
nvd.nist.gov
Web Technologies, Emerging Technologies, Identity & Access
CVE-2026-55532 affects PraisonAI, a multi-agent teams system, in versions prior to 4.6.58. The vulnerability exists in the MCP HTTP Stream _validate_origin function, which uses a startswith() check to validate request origins against an allowlist. An attacker can craft a malicious origin such as localhost.attacker.com that satisfies the localhost allowlist check due to the flawed string prefix matching. This allows cross-origin requests to be sent without CORS preflight by using Content-Type: text/plain, enabling unauthenticated access to the tools/call API endpoint without an API key. Successful exploitation can lead to unauthorized file writes that persist malicious agent instructions, potentially compromising the integrity of AI agent behavior. The vulnerability has been patched in PraisonAI version 4.6.58.
Technical details
Mitigation steps:
Affected products:
PraisonAI
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-55532
https://github.com/MervinPraison/PraisonAI/commit/2f9677abb2ea68eab864ee8b6a828fd0141612e1
https://github.com/MervinPraison/PraisonAI/releases/tag/v4.6.58
https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-pvph-5j39-v8qc
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
