---
id: GHSA-vp55-5c2v-3597
title: >-
  Duplicate Advisory: PraisonAI: Platform members can rewrite shared labels and
  owner issue labels without owner/admin authorization
summary: >-
  Duplicate Advisory: PraisonAI: Platform members can rewrite shared labels and
  owner issue labels without owner/admin authorization
severity: high
cvss: 6.5
cwe:
  - CWE-862
vendor: praisonai-platform
product: praisonai-platform
ecosystem: pip
affected:
  - praisonai-platform <= 0.1.8
published: '2026-07-15'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:58:20Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-vp55-5c2v-3597'
references:
  - url: >-
      https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-xxgv-vgvj-qvxh
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61440'
  - url: >-
      https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753
  - url: >-
      https://www.vulncheck.com/advisories/praisonai-platform-before-authorization-bypass-via-label-endpoints
  - url: 'https://github.com/advisories/GHSA-vp55-5c2v-3597'
tags:
  - ghsa
  - pip
ingestedAt: '2026-10-08T22:11:53.880Z'
---

## Overview

### Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-xxgv-vgvj-qvxh. This link is maintained to preserve external references.

### Original Description
PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. Attackers with workspace member privileges can exploit PATCH and POST/DELETE endpoints to alter shared label taxonomy and manipulate issue-label associations without owner or admin authorization.

## Affected packages

- `praisonai-platform <= 0.1.8`

## Remediation

Refer to the advisory for the patched release.
