CVE-2026-57112 | MervinPraison PraisonAI/praisonaiagents SseServerTransport mcp_server.py ToolsMCPServer.run_sse dns rebinding
A vulnerability, which was classified as critical, was found in MervinPraison PraisonAI and praisonaiagents. Impacted is the function ToolsMCPServer.run_sse of the file src/praisonai-agents/praisonaiagents/mcp/mcp_server.py of the component SseServerTransport. The manipulation results in reliance on reverse dns resolution.
This vulnerability is reported as CVE-2026-57112. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More