
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34953 is a critical authentication bypass vulnerability in PraisonAI's MCP (Multi-agent Communication Protocol) server, caused by a logic flaw in OAuthManager.validate_token(). The function returns True for any token not found in its internal store — which is empty by default — meaning any HTTP request bearing an arbitrary Bearer token is treated as fully authenticated. All versions of PraisonAI up to and including 4.5.96 (pip package) are affected; version 4.5.97 contains the fix. The vulnerability was published by the maintainer on March 31, 2026, and received a CVSS v3.1 base score of 9.1 (Critical) (GitHub Advisory, GHSA-98f9-fqg5-hvq5).
The root cause is an incorrect authorization flaw (CWE-863) in oauth.py. The validate_token() method iterates over self._tokens.values() to find a matching access token; if a match is found, it returns whether the token is unexpired. However, because _tokens is an empty dictionary by default, the loop never executes and control falls through to an unconditional return True at line 381 — effectively granting authentication to any caller. The vulnerable code path is: oauth.py:364 (source) → oauth.py:374 (loop miss) → oauth.py:381 (sink). The MCP server also binds to 0.0.0.0 by default with no API key required, maximizing the attack surface for any network-accessible attacker (GHSA-98f9-fqg5-hvq5, GitHub Advisory).
Any unauthenticated attacker with network access to the MCP HTTP server gains full access to all registered tools and agent capabilities, including praisonai.agent.run, praisonai.workflow.run, praisonai.containers.file_write, and skill loading — representing high confidentiality and integrity impact. Attackers can read and modify container files, execute arbitrary agent workflows, and invoke any of 50+ exposed tools without credentials. Because the server binds to 0.0.0.0 by default, internet-exposed deployments are at immediate risk of complete compromise (GHSA-98f9-fqg5-hvq5).
A public proof-of-concept exploit is available in the official GitHub security advisory, consisting of a single curl command requiring only network access to the MCP server — no credentials, no special tooling (GHSA-98f9-fqg5-hvq5). The EPSS score is approximately 0.022% (6th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (GitHub Advisory). No threat actor attribution has been reported. The vulnerability is trivially exploitable due to zero preconditions and a one-step attack.
0.0.0.0) using network scanners such as Shodan or Censys, or by directly probing known deployment addresses./mcp endpoint with any arbitrary Bearer token to confirm the server responds with HTTP 200 rather than 401.tools/list JSON-RPC call with a fabricated token to retrieve the full list of registered tools and agent capabilities:curl -s -X POST http://<target>:8080/mcp \
-H "Authorization: Bearer fake_token_abc123" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","method":"tools/list","id":1}'praisonai.agent.run, praisonai.workflow.run, or praisonai.containers.file_write using the same arbitrary Bearer token to execute agents, run workflows, or read/write container files./mcp endpoint with Authorization: Bearer <arbitrary_string> headers from unexpected or external IP addresses; high volume of tools/list or agent.run JSON-RPC calls from a single source.praisonai.agent.run, praisonai.workflow.run, or praisonai.containers.file_write from unauthenticated sessions.praisonai.containers.file_write; new or altered agent skill files loaded by the server.curl, wget), or Python subprocesses not initiated by legitimate workflows (GHSA-98f9-fqg5-hvq5).Upgrade PraisonAI to version 4.5.97 or later, which corrects the validate_token() logic to return False for unknown tokens instead of True (GHSA-98f9-fqg5-hvq5). If immediate upgrade is not possible, apply the following code fix manually in oauth.py — replace the trailing return True with return False and add JWT introspection for external tokens. Additionally, restrict network access to the MCP server using firewall rules or network segmentation so it is only reachable from trusted hosts, and avoid exposing the server on 0.0.0.0 in production environments.
The vulnerability was reported by security researcher YeranG30 and disclosed via the PraisonAI GitHub security advisory on March 31, 2026 (GHSA-98f9-fqg5-hvq5). A Dev.to article titled "7 CVEs in 48 Hours: How PraisonAI Got Completely Owned" highlighted this and related vulnerabilities, drawing community attention to the security posture of AI agent frameworks. Social media discussion appeared on Mastodon and Infosec.exchange, with security practitioners noting the ease of exploitation and the broader implications for MCP-based AI systems. Red Hat also tracked the vulnerability, indicating interest from enterprise security teams.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."