THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-pvph-5j39-v8qc (high) — PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

[GHSA] GHSA-pvph-5j39-v8qc (high) — PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

highgithub_advisoriesPublished 2026-08-25

GHSA-pvph-5j39-v8qc Severity: high CVE: CVE-2026-55532

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

### Summary

The PraisonAI MCP server exposes an HTTP-stream transport (praisonai mcp serve --transport http-stream) that binds to localhost and, by default, has no API key. Its only access co

Indicators of compromise

Original source: https://github.com/advisories/GHSA-pvph-5j39-v8qc