THREAT OPS › Threat News › [GHSA] GHSA-pvph-5j39-v8qc (high) — PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
[GHSA] GHSA-pvph-5j39-v8qc (high) — PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
GHSA-pvph-5j39-v8qc Severity: high CVE: CVE-2026-55532
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
### Summary
The PraisonAI MCP server exposes an HTTP-stream transport (praisonai mcp serve --transport http-stream) that binds to localhost and, by default, has no API key. Its only access co
Indicators of compromise
- CVE-2026-55532cve
- http://127.0.0.1url
- http://localhost.attacker.comurl
- https://127.0.0.1url
- http://127.0.0.1:8080/mcpurl
- http://attacker.comurl
- http://localhost.evil.comurl
- http://127.0.0.1.evil.comurl
- http://localhost-evil.comurl
Original source: https://github.com/advisories/GHSA-pvph-5j39-v8qc