<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T17:18:33.569813+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-368473</id>
    <title>EUVD-2026-368473</title>
    <updated>2026-10-04T17:18:33.620303+00:00</updated>
    <content>EUVD-2026-368473</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-368473"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57134</id>
    <title>fkie_cve-2026-57134</title>
    <updated>2026-10-04T17:18:33.620339+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth policies accept any non-empty Authorization header without calling auth.validate(), then return an authenticated result, allowing callers with invalid credentials to access MCP tools and resources protected by those policies. This issue is fixed in version 1.7.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-57134"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-4qq2-2j2x-x62c</id>
    <title>GHSA-4qq2-2j2x-x62c — npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation</title>
    <updated>2026-10-04T17:18:33.620372+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: praisonai</p>
<p>## Summary</p>
<p>The published npm package `praisonai` exports an `MCPSecurity` helper described in source as:</p>
<p>```text
MCP Security - Authentication, authorization, and rate limiting
Provides security policies for MCP servers.
```</p>
<p>Its `AuthMethod` type advertises five authentication methods:</p>
<p>```ts
export type AuthMethod = 'none' | 'api-key' | 'bearer' | 'basic' | 'oauth';
```</p>
<p>The authentication-policy evaluator, however, only validates credentials for `api-key` and `bearer`:</p>
<p>```ts
if (policy.auth.method === 'api-key' || policy.auth.method === 'bearer') {
    const valid = policy.auth.validate
        ? await policy.auth.validate(token)
        : this.validateApiKey(token);</p>
<p>if (!valid) {
        return { allowed: false, reason: 'Invalid credentials' };
    }
}</p>
<p>return { allowed: true, context: { authenticated: true } };
```</p>
<p>For `basic` and `oauth`, any non-empty `Authorization` header skips the supplied `validate` callback and returns allowed. A local PoV configures `auth.validate` to always return `false`; invalid `api-key` and `bearer` credentials are rejected, while invalid `basic` and `oauth` credentials are accepted without calling the validator.</p>
<p>This is a protection-mechanism failure in the exported npm MCP security helper. It is distinct from the separate issue that the npm `MCPServer` HTTP transport does not enforce authentication by default.</p>
<p>## Technical Details</p>
<p>`SecurityPolicy.auth` accepts both a method and a validator:</p>
<p>```ts
auth?: { method: AuthMethod;…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-4qq2-2j2x-x62c"/>
  </entry>
</feed>
