All verified exploits

CVE-2026-34953 MCP Server OAuth Token Bypass

Deterministic critical PraisonAI Added cve-verified-cve-2026-34953

Detects PraisonAI MCP server instances where the OAuth validate_token() method returns True for any unknown Bearer token. An unauthenticated attacker can send a fabricated token to the /mcp endpoint and gain full access to all registered MCP tools — agent execution, file read/write, workflow operations, and skill loading. Update to PraisonAI 4.5.97 or later.

Is your app exploitable through CVE-2026-34953?

Scan your domain free