CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-p75f-6fp4-p57w: PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai

criticalCVSS 9.8CVE-2026-57124
Unauthenticated PraisonAI UI MCP connect endpoint executes attacker-chosen local commands Summary PraisonAI v4.6.48 exposes the PraisonAIUI MCP client management API through the default UI host apps without authentication. A remote unauthenticated client can send POST /api/mcp/connect with a command and args field. The endpoint passes those values into the MCP stdio client, which starts the attacker-selected local process as the PraisonAI UI service user. The issue is reachable through PraisonAI's hosted UI integration (praisonai ui, praisonai ui agents, praisonai claw, and any app using praisonai.integration.host_app.create_host_app() / build_host_app()). praisonai ui and related Typer UI commands bind to 0.0.0.0 by default. Affected Versions Confirmed affected: - praisonai v4.6.48 - Commit tested: d5f1114aaf1a2e9f121a6e66b929149ca2201f1d - Tag tested: v4.6.48 - Pinned UI dependency: aiui==0.3.121 from src/praisonai/uv.lock Likely affected: - Any PraisonAI release that exposes aiui / praisonaiui create_app() through the PraisonAI UI host apps without authentication and includes the mcp dependency. I only confirmed the latest release during this audit. Severity Reasoning: - AV: the vulnerable endpoint is an HTTP API route. - AC: a single POST request is sufficient. - PR: default UI host apps do not require credentials unless opt-in auth is configured. - UI: no victim interaction is needed after the server is running. - S: code executes in the PraisonAI UI server process context. - C/I/A: arbitrary local command execution permits secret exfiltration, file tampering, and service disruption. Root Cause PraisonAI depends on MCP by default and exposes PraisonAIUI via optional UI extras: - src/praisonai/pyproject.toml:11 includes base dependencies. - src/praisonai/pyproject.toml:19 includes mcp>=1.20.0. - src/praisonai/pyproject.toml:25 defines the ui extra with aiui>=0.3.121,<0.4. - src/praisonai/pyproject.toml:197 defines the claw extra with aiui[all]>=0.3

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
critical — CVSS 9.8
Published
2026-06-18
Last updated
2026-07-20
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-p75f-6fp4-p57w

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-57124coverage & exploitation statusNVD · CVE.org

More from GitHub Security Advisories