CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-57124

criticalCVSS 9.8covered by 1 sourcefirst seen 2026-06-18
Unauthenticated PraisonAI UI MCP connect endpoint executes attacker-chosen local commands Summary PraisonAI v4.6.48 exposes the PraisonAIUI MCP client management API through the default UI host apps without authentication. A remote unauthenticated client can send POST /api/mcp/connect with a command and args field. The endpoint passes those values into the MCP stdio client, which starts the attacker-selected local process as the PraisonAI UI service user. The issue is reachable through PraisonAI's hosted UI integration (praisonai ui, praisonai ui agents, praisonai claw, and any app using praisonai.integration.host_app.create_host_app() / build_host_app()). praisonai ui and related Typer UI commands bind to 0.0.0.0 by default. Affected Versions Confirmed affected: - praisonai v4.6.48 - Commit tested: d5f1114aaf1a2e9f121a6e66b929149ca2201f1d - Tag tested: v4.6.48 - Pinned UI dependency: aiui==0.3.121 from src/praisonai/uv.lock Likely affected: - Any PraisonAI release that exposes aiui / praisonaiui create_app() through the PraisonAI UI host apps without authentication and includes the mcp dependency. I only confirmed the latest release during this audit. Severity Reasoning: - AV: the vulnerable endpoint is an HTTP API route. - AC: a single POST request is sufficient. - PR: default UI host apps do not require credentials unless opt-in auth is configured. - UI: no victim interaction is needed after the server is running. - S: code executes in the PraisonAI UI server process context. - C/I/A: arbitrary local command execution permits secret exfiltration, file tampering, and service disruption. Root Cause PraisonAI depends on MCP by default and exposes PraisonAIUI via optional UI extras: - src/praisonai/pyproject.toml:11 includes base dependencies. - src/praisonai/pyproject.toml:19 includes mcp>=1.20.0. - src/praisonai/pyproject.toml:25 defines the ui extra with aiui>=0.3.121,<0.4. - src/praisonai/pyproject.toml:197 defines the claw extra with aiui[all]>=0.3

⚡ Watch CVE-2026-57124

Get an email if CVE-2026-57124 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-57124

CVE.org record

Embed the live status

CVE-2026-57124 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-57124 status](https://www.csirts.com/badge/CVE-2026-57124)](https://www.csirts.com/cve/CVE-2026-57124)