Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-48169High· 8.8PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key…
CVE-2026-57121High· 8.1PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
CVE-2026-58653Medium· 4.3praisonai-platform: Authorization Bypass Through User-Controlled Key
GHSA-rh39-9c67-59mhHigh· 8.1PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
GHSA-f38v-77qj-h4jqCritical· 9.8praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)
GHSA-cwj8-7gp2-ggcwCritical· 9.8praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery
GHSA-2fjj-qqg8-fg7xMedium· 4.3praisonai-platform: Authorization Bypass Through User-Controlled Key
CVE-2026-47419High· 8.3praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR
CVE-2026-47415High· 8.3praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR
CVE-2026-47411Medium· 6.5praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}
CVE-2026-47412High· 8.1praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}
CVE-2026-47417High· 8.1praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR
CVE-2026-47418High· 8.1praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR
CVE-2026-47409High· 8.1praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role
CVE-2026-47405High· 8.8PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership
CVE-2026-47399High· 8.8PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID
CVE-2026-47414High· 7.6praisonai-platform: Label endpoints' unchecked label_id/issue_id enable cross-workspace label IDOR (edit, delete, link)
CVE-2026-47406High· 8.1praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks
CVE-2026-47408Medium· 6.5praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.