Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-58446— Presenton < 0.8.8-beta - Authentication Bypass of Session Auth via Unprotected MCP Endpoint

CVSS 6.5 · Medium EPSS 0.44% · P36

Affected Version Matrix 1

VendorProductVersion RangeStatus
presentonpresenton< 0.8.8-betaaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-58446

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Presenton < 0.8.8-beta - Authentication Bypass of Session Auth via Unprotected MCP Endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authentication (AUTH_USERNAME/AUTH_PASSWORD), is reachable unauthenticated at /mcp because the nginx front-end does not apply the auth_request gate to that path and the MCP server auto-mints a valid internal session token for the configured user. A remote unauthenticated attacker can invoke MCP tools such as generate_presentation, performing authenticated application actions, consuming the operators configured LLM API keys, and creating presentations in the operators instance. The Electron desktop build is not affected (MCP disabled).
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
Presenton 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Presenton Presenton是Presenton公司开源的一款开源的 AI 演示文稿生成器,支持通过 API 集成或自托管,利用自定义模板快速生成可编辑的 PPTX/PDF 格式幻灯片,无供应商锁定。 Presenton 0.8.8-beta之前版本存在授权问题漏洞,该漏洞源于nginx前端未对/mcp路径应用auth_request网关且MCP服务器自动为配置用户生成有效内部会话令牌,导致远程未经验证攻击者可调用MCP工具(如generate_presentation),执行已认证应用操作,消
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
presentonpresenton 0 ~ 0.8.8-beta -

II. Public POCs for CVE-2026-58446

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-58446

登录查看更多情报信息。

Patches & Fixes for CVE-2026-58446 (2)

News Coverage for CVE-2026-58446 (1)

Other References for CVE-2026-58446 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-58446

No comments yet


Leave a comment