CVE-2026-57124 | MervinPraison PraisonAI up to 4.6.58 MCP Connect /api/mcp/connect args command injection

SecurityVulns

A vulnerability, which was classified as critical, was found in MervinPraison PraisonAI up to 4.6.58. Affected by this issue is some unknown functionality of the file /api/mcp/connect of the component MCP Connect. Such manipulation of the argument args leads to command injection.

This vulnerability is referenced as CVE-2026-57124. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component.VulDB Recent EntriesRead More