VYPR

MCP HTTP Stream transport

by PraisonAI

CVEs (1)

  • CVE-2026-55529MedAug 25, 2026
    risk 0.38cvss 6.9epss

    PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_origin method accepts request_origin.startswith(allowed), so the attacker-controlled localhost.evil.example HTTP origin matches the localhost allowlist. Without an API key, a…