CVE-2026-34953: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-34953 is a critical authentication bypass vulnerability in PraisonAI's MCP (Multi-agent Communication Protocol) server, caused by a logic flaw in OAuthManager.validate_token(). The function returns True for any token not found in its internal store — which is empty by default — meaning any HTTP request bearing an arbitrary Bearer token is treated as fully authenticated. All versions of PraisonAI up to and including 4.5.96 (pip package) are affected; version 4.5.97 contains the fix. The vulnerability was published by the maintainer on March 31, 2026, and received a CVSS v3.1 base score of 9.1 (Critical) (GitHub Advisory, GHSA-98f9-fqg5-hvq5).

Technical details

The root cause is an incorrect authorization flaw (CWE-863) in oauth.py. The validate_token() method iterates over self._tokens.values() to find a matching access token; if a match is found, it returns whether the token is unexpired. However, because _tokens is an empty dictionary by default, the loop never executes and control falls through to an unconditional return True at line 381 — effectively granting authentication to any caller. The vulnerable code path is: oauth.py:364 (source) → oauth.py:374 (loop miss) → oauth.py:381 (sink). The MCP server also binds to 0.0.0.0 by default with no API key required, maximizing the attack surface for any network-accessible attacker (GHSA-98f9-fqg5-hvq5, GitHub Advisory).

Impact

Any unauthenticated attacker with network access to the MCP HTTP server gains full access to all registered tools and agent capabilities, including praisonai.agent.run, praisonai.workflow.run, praisonai.containers.file_write, and skill loading — representing high confidentiality and integrity impact. Attackers can read and modify container files, execute arbitrary agent workflows, and invoke any of 50+ exposed tools without credentials. Because the server binds to 0.0.0.0 by default, internet-exposed deployments are at immediate risk of complete compromise (GHSA-98f9-fqg5-hvq5).

Exploitability

A public proof-of-concept exploit is available in the official GitHub security advisory, consisting of a single curl command requiring only network access to the MCP server — no credentials, no special tooling (GHSA-98f9-fqg5-hvq5). The EPSS score is approximately 0.022% (6th percentile), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (GitHub Advisory). No threat actor attribution has been reported. The vulnerability is trivially exploitable due to zero preconditions and a one-step attack.

Exploitation steps

  1. Reconnaissance: Identify internet-facing PraisonAI MCP server instances (default port 8080, binding to 0.0.0.0) using network scanners such as Shodan or Censys, or by directly probing known deployment addresses.
  2. Confirm vulnerability: Send a test HTTP POST request to the /mcp endpoint with any arbitrary Bearer token to confirm the server responds with HTTP 200 rather than 401.
  3. Enumerate tools: Issue a tools/list JSON-RPC call with a fabricated token to retrieve the full list of registered tools and agent capabilities:
curl -s -X POST http://<target>:8080/mcp \
  -H "Authorization: Bearer fake_token_abc123" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","method":"tools/list","id":1}'
  1. Invoke privileged tools: Call high-impact tools such as praisonai.agent.run, praisonai.workflow.run, or praisonai.containers.file_write using the same arbitrary Bearer token to execute agents, run workflows, or read/write container files.
  2. Achieve objective: Leverage agent execution or file write capabilities for data exfiltration, persistent access, or further lateral movement within the environment (GHSA-98f9-fqg5-hvq5).

Indicators of compromise

  • Network: HTTP POST requests to /mcp endpoint with Authorization: Bearer <arbitrary_string> headers from unexpected or external IP addresses; high volume of tools/list or agent.run JSON-RPC calls from a single source.
  • Logs: MCP server access logs showing 200 OK responses to requests bearing unrecognized or randomly generated Bearer tokens; repeated invocations of praisonai.agent.run, praisonai.workflow.run, or praisonai.containers.file_write from unauthenticated sessions.
  • File System: Unexpected files created or modified in container directories via praisonai.containers.file_write; new or altered agent skill files loaded by the server.
  • Process: Unusual child processes spawned by the PraisonAI MCP server process, particularly shell commands, data exfiltration utilities (curl, wget), or Python subprocesses not initiated by legitimate workflows (GHSA-98f9-fqg5-hvq5).

Mitigation and workarounds

Upgrade PraisonAI to version 4.5.97 or later, which corrects the validate_token() logic to return False for unknown tokens instead of True (GHSA-98f9-fqg5-hvq5). If immediate upgrade is not possible, apply the following code fix manually in oauth.py — replace the trailing return True with return False and add JWT introspection for external tokens. Additionally, restrict network access to the MCP server using firewall rules or network segmentation so it is only reachable from trusted hosts, and avoid exposing the server on 0.0.0.0 in production environments.

Community reactions

The vulnerability was reported by security researcher YeranG30 and disclosed via the PraisonAI GitHub security advisory on March 31, 2026 (GHSA-98f9-fqg5-hvq5). A Dev.to article titled "7 CVEs in 48 Hours: How PraisonAI Got Completely Owned" highlighted this and related vulnerabilities, drawing community attention to the security posture of AI agent frameworks. Social media discussion appeared on Mastodon and Infosec.exchange, with security practitioners noting the ease of exploitation and the broader implications for MCP-based AI systems. Red Hat also tracked the vulnerability, indicating interest from enterprise security teams.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management