CVE-2026-62179Medium· 6.5▾ SunlitPraisonAI is a multi-agent teams system. In `praisonai-platform` prior to version 0.1.9, issue dependency deletion can be authorized against the wrong side of a dependency edge. A workspace member cannot delete a dependency through the o…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
PraisonAI is a multi-agent teams system. In praisonai-platform prior to version 0.1.9, issue dependency deletion can be authorized against the wrong side of a dependency edge. A workspace member cannot delete a dependency through the owner-created issue endpoint, but can delete the same dependency through a member-owned related issue endpoint because the route accepts either endpoint and checks delete permission only against the caller-selected URL issue. Version 0.1.9 patches the issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
praisonai-platform <= 0.1.8Patched in:
praisonai-platform 0.1.9Connected by shared product, vendor, weakness, or advisory.
CVE-2026-48169High· 8.8PraisonAI is a multi-agent teams system
CVE-2025-12925High· 7.3A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224
CVE-2026-57121High· 8.1PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
CVE-2026-47415High· 8.3praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR
CVE-2026-47409High· 8.1praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role
CVE-2026-47411Medium· 6.5praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}