GHSA-p75f-6fp4-p57w: PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
Unauthenticated PraisonAI UI MCP connect endpoint executes attacker-chosen local commands
Summary
PraisonAI v4.6.48 exposes the PraisonAIUI MCP client management API through the default UI host apps without authentication. A remote unauthenticated client can send POST /api/mcp/connect with a command and args field. The endpoint passes those values into the MCP stdio client, which starts the attacker-selected local process as the PraisonAI UI service user.
The issue is reachable through PraisonAI's hosted UI integration (praisonai ui, praisonai ui agents, praisonai claw, and any app using praisonai.integration.host_app.create_host_app() / build_host_app()). praisonai ui and related Typer UI commands bind to 0.0.0.0 by default.
Affected Versions
Confirmed affected:
- praisonai v4.6.48
- Commit tested: d5f1114aaf1a2e9f121a6e66b929149ca2201f1d
- Tag tested: v4.6.48
- Pinned UI dependency: aiui==0.3.121 from src/praisonai/uv.lock
Likely affected:
- Any PraisonAI release that exposes aiui / praisonaiui create_app() through the PraisonAI UI host apps without authentication and includes the mcp dependency. I only confirmed the latest release during this audit.
Severity
Reasoning:
- AV: the vulnerable endpoint is an HTTP API route.
- AC: a single POST request is sufficient.
- PR: default UI host apps do not require credentials unless opt-in auth is configured.
- UI: no victim interaction is needed after the server is running.
- S: code executes in the PraisonAI UI server process context.
- C/I/A: arbitrary local command execution permits secret exfiltration, file tampering, and service disruption.
Root Cause
PraisonAI depends on MCP by default and exposes PraisonAIUI via optional UI extras:
- src/praisonai/pyproject.toml:11 includes base dependencies.
- src/praisonai/pyproject.toml:19 includes mcp>=1.20.0.
- src/praisonai/pyproject.toml:25 defines the ui extra with aiui>=0.3.121,<0.4.
- src/praisonai/pyproject.toml:197 defines the claw extra with aiui[all]>=0.3
Details
Original advisory: https://github.com/advisories/GHSA-p75f-6fp4-p57w
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-57124 | coverage & exploitation status | NVD · CVE.org |
More from GitHub Security Advisories
- mediumGHSA-xm43-3m56-w3wf: Ghost: Paid gift memberships obtainable at minimal cost via the donations feature2026-08-04
- mediumGHSA-chgm-3698-jm42: Ghost: Member existence leak via magic link sign-in response2026-08-04
- highGHSA-xpp7-93x6-v29m: XSS in Ghost's ActivityPub client2026-08-04
- mediumGHSA-7mpp-r37j-x5wh: Ghost: Session Fixation in Ghost Admin2026-08-04
- mediumGHSA-cjc9-q5gf-327p: Ghost: Theme Upload Path Traversal2026-08-04