Skip to content

MCPA-2026-0043

mediumauth-missingCVSS 7.3

PraisonAI MCP HTTP-stream transport is unauthenticated by default (CVE-2026-61427)

PraisonAI (PyPI: praisonai) before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option defaults to None and the server only enforces Authorization/Bearer checks when an API key is configured, so 'praisonai mcp serve --transport http-stream' without an API key accepts unauthenticated MCP requests. Fixed in 4.6.78. Package mapping (PyPI praisonai) verified independently — the GHSA carries no package mapping.

Affected packages

EcosystemPackageAffected versions
pypipraisonai
>= 0, < 4.6.78
Package mapping verified independently; the NVD/GHSA entry names the project but maps no registry package.

Identifiers

CVE-2026-61427GHSA-5866-9272-qcfvGHSA-hc5v-gxvj-58whCWE-20

References

Timeline

  • Published: 2026-07-15

← All advisories