<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T10:35:24.849670+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-370511</id>
    <title>EUVD-2026-370511</title>
    <updated>2026-10-08T10:35:24.895117+00:00</updated>
    <content>EUVD-2026-370511</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-370511"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-57139</id>
    <title>fkie_cve-2026-57139</title>
    <updated>2026-10-08T10:35:24.895164+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/server.ts binds without a host restriction and forwards every HTTP POST request to handleRequest() without authentication or authorization. Any network client that can reach the port can call tools/list, tools/call, resources/read, or prompts/get, causing registered handlers to run with server-side credentials and process privileges or disclose registered data. An initial remediation was released in version 1.7.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-57139"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-j4f3-55x4-r6q2</id>
    <title>GHSA-j4f3-55x4-r6q2 — npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call</title>
    <updated>2026-10-08T10:35:24.895244+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: praisonai</p>
<p>## Summary</p>
<p>The published npm package `praisonai` exports a TypeScript `MCPServer` that can expose tools, resources, and prompts over an HTTP JSON-RPC transport with:</p>
<p>```ts
await server.start({ port: 3000 });
```</p>
<p>The HTTP transport has no authentication or authorization path. `MCPServerConfig` does not expose an auth/security setting, `startHttp()` ignores the `Authorization` header, and every POST request is parsed and forwarded directly to `handleRequest()`. That request handler dispatches sensitive MCP methods such as `tools/call`, `resources/read`, and `prompts/get`.</p>
<p>The implementation also calls `this.httpServer.listen(port)` without a host argument. In Node.js this binds to the unspecified address; the local PoV observed `{ address: "::", family: "IPv6" }`, making the service reachable on all interfaces on systems where the port is exposed.</p>
<p>This lets any network client that can reach the HTTP port list tools and invoke registered server-side tools without credentials. Supplying `Authorization: Bearer invalid` makes no difference.</p>
<p>## Technical Details</p>
<p>`MCPServerConfig` exposes server metadata, tools/resources/prompts, stdio, port, and logging. It does not expose an auth token, authorization policy, `MCPSecurity` instance, authorization callback, or loopback-only option:</p>
<p>```text
src/praisonai-ts/src/mcp/server.ts
  57: export interface MCPServerConfig {
  63:     tools?: MCPServerTool[];
  65:     resources?: MCPResource[];
  67:     prompts?: MCPPrompt[];
  69:…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-j4f3-55x4-r6q2"/>
  </entry>
</feed>
