praisonai-platform has 19 CVEs on record. Disclosures have slowed: 1 in the last 90 days after 18 in the 90 before. The busiest recent month was June 2026 with 12. The median CVSS is 8.1 (high), with 2 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.1
- Publish → KEV
- —
- Last 90 days
- 1 prev 18
Weakness classes
Products
- praisonai-platform 19
Worst active — by depth score
GHSA-f38v-77qj-h4jqCritical· 9.8praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)54GHSA-cwj8-7gp2-ggcwCritical· 9.8praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery54CVE-2026-47405High· 8.8PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership49CVE-2026-47399High· 8.8PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID49CVE-2026-48169High· 8.8PraisonAI is a multi-agent teams system48
praisonai-platform vulnerabilities
CVEs affecting praisonai-platform, newest first. Open any entry for full detail, references, and exploit status.
19 CVEsRSS
CVE-2026-48169High· 8.8PraisonAI is a multi-agent teams system
PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key…
CVE-2026-57121High· 8.1PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
CVE-2026-58653Medium· 4.3praisonai-platform: Authorization Bypass Through User-Controlled Key
praisonai-platform: Authorization Bypass Through User-Controlled Key
GHSA-rh39-9c67-59mhHigh· 8.1PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
GHSA-f38v-77qj-h4jqCritical· 9.8praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)
praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)
GHSA-cwj8-7gp2-ggcwCritical· 9.8praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery
praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery
GHSA-2fjj-qqg8-fg7xMedium· 4.3praisonai-platform: Authorization Bypass Through User-Controlled Key
praisonai-platform: Authorization Bypass Through User-Controlled Key
CVE-2026-47419High· 8.3praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR
praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR
CVE-2026-47415High· 8.3praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR
praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR
CVE-2026-47411Medium· 6.5praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}
praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}
CVE-2026-47412High· 8.1praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}
praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}
CVE-2026-47417High· 8.1praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR
praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR
CVE-2026-47418High· 8.1praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR
praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR
CVE-2026-47409High· 8.1praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role
praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role
CVE-2026-47405High· 8.8PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership
PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership
CVE-2026-47399High· 8.8PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID
PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID
CVE-2026-47414High· 7.6praisonai-platform: Label endpoints' unchecked label_id/issue_id enable cross-workspace label IDOR (edit, delete, link)
praisonai-platform: Label endpoints' unchecked label_id/issue_id enable cross-workspace label IDOR (edit, delete, link)
CVE-2026-47406High· 8.1praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks
praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks
CVE-2026-47408Medium· 6.5praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership
praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership