CVE-2026-57124
Unauthenticated PraisonAI UI MCP connect endpoint executes attacker-chosen local commands
Summary
PraisonAI v4.6.48 exposes the PraisonAIUI MCP client management API through the default UI host apps without authentication. A remote unauthenticated client can send POST /api/mcp/connect with a command and args field. The endpoint passes those values into the MCP stdio client, which starts the attacker-selected local process as the PraisonAI UI service user.
The issue is reachable through PraisonAI's hosted UI integration (praisonai ui, praisonai ui agents, praisonai claw, and any app using praisonai.integration.host_app.create_host_app() / build_host_app()). praisonai ui and related Typer UI commands bind to 0.0.0.0 by default.
Affected Versions
Confirmed affected:
- praisonai v4.6.48
- Commit tested: d5f1114aaf1a2e9f121a6e66b929149ca2201f1d
- Tag tested: v4.6.48
- Pinned UI dependency: aiui==0.3.121 from src/praisonai/uv.lock
Likely affected:
- Any PraisonAI release that exposes aiui / praisonaiui create_app() through the PraisonAI UI host apps without authentication and includes the mcp dependency. I only confirmed the latest release during this audit.
Severity
Reasoning:
- AV: the vulnerable endpoint is an HTTP API route.
- AC: a single POST request is sufficient.
- PR: default UI host apps do not require credentials unless opt-in auth is configured.
- UI: no victim interaction is needed after the server is running.
- S: code executes in the PraisonAI UI server process context.
- C/I/A: arbitrary local command execution permits secret exfiltration, file tampering, and service disruption.
Root Cause
PraisonAI depends on MCP by default and exposes PraisonAIUI via optional UI extras:
- src/praisonai/pyproject.toml:11 includes base dependencies.
- src/praisonai/pyproject.toml:19 includes mcp>=1.20.0.
- src/praisonai/pyproject.toml:25 defines the ui extra with aiui>=0.3.121,<0.4.
- src/praisonai/pyproject.toml:197 defines the claw extra with aiui[all]>=0.3
⚡ Watch CVE-2026-57124
Get an email if CVE-2026-57124 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Advisory coverage (1)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-57124)