SEPTEMBER 16, 2026
Live Feed
Back to database
Case File

CVE-2026-57112

HIGH · CVSS 8.3 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

PraisonAI versions 0.6.0 to 1.6.59 and 3.10.0 to 4.6.59 are vulnerable due to improper handling of Host and Origin headers in the ToolsMCPServer.run_sse() function, allowing attackers to exploit DNS rebinding to interact with the server's endpoints. This vulnerability enables unauthorized enumeration and invocation of registered tools with the privileges of the server user, posing a significant risk to system integrity. Organizations using affected versions should prioritize patching to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57112
Severity
HIGH
CVSS
8.3
EPSS
0.19%

Original NVD Description

PraisonAI is a multi-agent teams system. From praisonaiagents 0.6.0 until 1.6.59 and PraisonAI 3.10.0 until 4.6.59, ToolsMCPServer.run_sse() in src/praisonai-agents/praisonaiagents/mcp/mcp_server.py mounts SseServerTransport on the legacy /sse and /messages/ endpoints without default Host, Origin, or authentication enforcement. A malicious website can use DNS rebinding against a reachable local or internal SSE server, supply attacker-controlled Host and Origin headers, enumerate registered tools, and invoke them with the server user's privileges. The Streamable HTTP transport rejects the same hostile Origin, which isolates the flaw to the legacy SSE wrapper. An initial remediation was released in praisonaiagents 1.6.59 and PraisonAI 4.6.59.