Description
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The dependency endpoints (`POST/GET /workspaces/{workspace_id}/issues/{issue_id}/dependencies` and `DELETE .../dependencies/{dep_id}`) gate access on `require_workspace_member(workspace_id)` only, then dispatch to `DependencyService` calls that take URL/body-supplied issue and dependency IDs without verifying any of them belong to the membership-checked workspace. Most damaging: `create_dependency` accepts `body.depends_on_issue_id` from the request body — that ID is checked against nothing — letting an attacker create a "blocks" or "related" link between any two issues anywhere in the database. PraisonAI Platform version 0.1.4 patches the issue.
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an Insecure Direct Object Reference (IDOR) affecting PraisonAI Platform before version 0.1.4. The dependency endpoints (POST/GET /workspaces/{workspace_id}/issues/{issue_id}/dependencies and DELETE /workspaces/{workspace_id}/issues/{issue_id}/dependencies/{dep_id}) validate only that the user belongs to the target workspace, then forward the supplied issue_id, dep_id, and depends_on_issue_id to internal services without checking that these identifiers belong to the same workspace. This omission lets an authenticated member of any workspace craft requests that link, read, or delete dependencies between issues in unrelated workspaces, effectively creating or manipulating cross‑workspace issue relationships. The exploitation can lead to unauthorized data exposure, integrity tampering, and potential deletion of critical dependency information.

Affected Systems

The flaw affects PraisonAI Platform developed by MervinPraison. All releases prior to version 0.1.4 are vulnerable. Attackers can target the POST/GET /workspaces/{workspace_id}/issues/{issue_id}/dependencies and DELETE /workspaces/{workspace_id}/issues/{issue_id}/dependencies/{dep_id} endpoints to exploit the issue.

Risk and Exploitability

The CVSS score of 8.1 reflects a high severity attack that can compromise confidentiality and integrity of issue data across workspaces. However, the EPSS score of less than 1% indicates a low current exploitation probability, and the vulnerability is not yet listed in the CISA KEV catalog. Likely exploitation requires an authenticated user who is a member of the target workspace, with the attacker then redirecting or deleting dependencies that link to or from other workspaces. Once an attacker can forge these links, they can manipulate issue visibility, create confusion, or potentially access sensitive information tied to those issues.

Generated by OpenCVE AI on July 30, 2026 at 17:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PraisonAI Platform to version 0.1.4 or later, which includes the correct workspace membership checks for dependency operations.
  • If upgrading is not immediately possible, implement a temporary server-side validation layer that verifies the ownership of both the issue and dependency IDs against the workspace before processing the request.
  • Monitor REST traffic and audit logs for abnormal or cross-workspace linking activity, and alert on suspicious dependency changes.
  • As an interim measure, restrict or disable the dependency endpoints for users who are not explicitly authorized to manage inter‑workspace relationships.

Generated by OpenCVE AI on July 30, 2026 at 17:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4x6r-9v57-3gqw praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks
History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Tue, 21 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Description PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The dependency endpoints (`POST/GET /workspaces/{workspace_id}/issues/{issue_id}/dependencies` and `DELETE .../dependencies/{dep_id}`) gate access on `require_workspace_member(workspace_id)` only, then dispatch to `DependencyService` calls that take URL/body-supplied issue and dependency IDs without verifying any of them belong to the membership-checked workspace. Most damaging: `create_dependency` accepts `body.depends_on_issue_id` from the request body — that ID is checked against nothing — letting an attacker create a "blocks" or "related" link between any two issues anywhere in the database. PraisonAI Platform version 0.1.4 patches the issue.
Title praisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace ownership check, cross-workspace issue linking + read + delete IDOR
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-21T17:22:05.161Z

Reserved: 2026-05-19T19:37:43.525Z

Link: CVE-2026-47406

cve-icon Vulnrichment

Updated: 2026-07-21T17:11:02.512Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:15:12Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key