High severity7.6NVD Advisory· Published Aug 25, 2026
CVE-2026-55532
CVE-2026-55532
Description
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses request_origin.startswith(allowed), allowing the attacker-controlled localhost.attacker.com HTTP origin to satisfy the localhost allowlist. A webpage can send Content-Type: text/plain requests without preflight and invoke tools/call without an API key, including file writes that persist agent instructions. This issue is fixed in version 4.6.58.
Affected products
2Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.