Detects PraisonAI MCP server instances where the OAuth validate_token() method returns True for any unknown Bearer token. An unauthenticated attacker can send a fabricated token to the /mcp endpoint and gain full access to all registered MCP tools — agent execution, file read/write, workflow operations, and skill loading. Update to PraisonAI 4.5.97 or later.
Is your app exploitable through CVE-2026-34953?
Scan your domain free