CVE-2026-57134

PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth policies accept any non-empty Authorization header without calling auth.validate(), then return an authenticated result, allowing callers with invalid credentials to access MCP tools and resources protected by those policies. This issue is fixed in version 1.7.2.

Scoring

Severity
HIGH
CVSS base score
8.2
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
EPSS probability
0.30%
CWE
CWE-287, CWE-288, CWE-863
Published
2026-09-15
Last modified
2026-09-15

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs