MCPA-2026-0043
mediumauth-missingCVSS 7.3
PraisonAI MCP HTTP-stream transport is unauthenticated by default (CVE-2026-61427)
PraisonAI (PyPI: praisonai) before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option defaults to None and the server only enforces Authorization/Bearer checks when an API key is configured, so 'praisonai mcp serve --transport http-stream' without an API key accepts unauthenticated MCP requests. Fixed in 4.6.78. Package mapping (PyPI praisonai) verified independently — the GHSA carries no package mapping.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| pypi | praisonai | >= 0, < 4.6.78 Package mapping verified independently; the NVD/GHSA entry names the project but maps no registry package. |
Identifiers
CVE-2026-61427GHSA-5866-9272-qcfvGHSA-hc5v-gxvj-58whCWE-20
References
- advisory https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-hc5v-gxvj-58wh
- web https://nvd.nist.gov/vuln/detail/CVE-2026-61427
Timeline
- Published: 2026-07-15