Description
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The `GET /workspaces/{workspace_id}/issues/{issue_id}/activity` endpoint is gated by `require_workspace_member(workspace_id)` and dispatches to `ActivityService.list_for_issue(issue_id)`, which executes `SELECT * FROM activity WHERE issue_id = :issue_id` with no workspace constraint. A user who is a member of any workspace can read the full activity log of any issue across the entire multi-tenant deployment. PraisonAI Platform version 0.1.4 patches the issue.
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

PraisonAI Platform, the base layer for its multi‑agent teams system, has an Insecure Direct Object Reference in all releases before version 0.1.4. The GET /workspaces/{workspace_id}/issues/{issue_id}/activity endpoint, which is protected only by a workspace‑membership check, internally queries the activity table without filtering by workspace. As a result, any authenticated member of any workspace can read the entire activity log for any issue in the platform, even those unrelated to the member’s own workspace. This flaw allows the disclosure of potentially sensitive operational information and can be exploited by any workspace participant to log details they are not authorized to view.

Affected Systems

The issue impacts PraisonAI Platform versions prior to 0.1.4. The platform is provided by MervinPraison under the product praisonai-platform. Users running any version before 0.1.4 should seek an update.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests that widespread exploitation is unlikely, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires being a member of any workspace; an attacker can then send the vulnerable GET request and receive the activity data of any issue irrespective of the originating workspace.

Generated by OpenCVE AI on July 30, 2026 at 17:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PraisonAI Platform to version 0.1.4 or later to apply the fix that enforces workspace constraints on activity queries.
  • Ensure that workspace membership is limited to only authorized users; consider revoking membership of users who no longer need access to reduce the attack surface.
  • Review existing data access controls in the platform and enforce tenant isolation at the database query level to prevent similar Insecure Direct Object Reference issues from persisting in future releases.

Generated by OpenCVE AI on July 30, 2026 at 17:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-27p4-pjqv-whgj praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership
History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Thu, 23 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Description PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The `GET /workspaces/{workspace_id}/issues/{issue_id}/activity` endpoint is gated by `require_workspace_member(workspace_id)` and dispatches to `ActivityService.list_for_issue(issue_id)`, which executes `SELECT * FROM activity WHERE issue_id = :issue_id` with no workspace constraint. A user who is a member of any workspace can read the full activity log of any issue across the entire multi-tenant deployment. PraisonAI Platform version 0.1.4 patches the issue.
Title praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-23T14:25:16.518Z

Reserved: 2026-05-19T19:37:43.525Z

Link: CVE-2026-47408

cve-icon Vulnrichment

Updated: 2026-07-23T14:25:04.563Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:15:12Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key