THREAT OPS › Threat News › [GHSA] GHSA-wj6g-v78p-6fx3 (medium) — PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
[GHSA] GHSA-wj6g-v78p-6fx3 (medium) — PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
GHSA-wj6g-v78p-6fx3 Severity: medium CVE: CVE-2026-55529
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
### Summary
PraisonAI's MCP HTTP Stream transport uses an unsafe prefix match when validating the `Origin` header. The default localhost allowlist includes origins such as `http://localhost
Indicators of compromise
- CVE-2026-55529cve
- http://localhost`url
- http://localhost.evil.example`url
- http://127.0.0.1url
- https://127.0.0.1url
- https://evil.exampleurl
- http://localhost.evil.exampleurl
- https://evil.example`url
Original source: https://github.com/advisories/GHSA-wj6g-v78p-6fx3