Description
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The project CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/projects/{project_id}` and `GET .../{project_id}/stats`) gate access on `require_workspace_member(workspace_id)` only, then resolve `project_id` through `ProjectService.get(project_id)` / `update(project_id, ...)` / `delete(project_id)` / `get_stats(project_id)`. None of these calls thread `workspace_id` through to constrain the lookup. A user who is a member of any workspace `W1` can read, modify, delete, or read stats for projects that belong to a different workspace `W2`. PraisonAI Platform version 0.1.4 patches the issue.
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises because the platform’s project create, update, delete, and statistics endpoints perform a workspace membership check only on the workspace identifier and then resolve the project identifier without re‑validating that the project belongs to that workspace. This lack of ownership verification permits an authenticated user who is a member of any workspace to read, modify, delete, or gather statistics for projects residing in other workspaces, exposing sensitive data and allowing integrity tampering. The weakness is a classic IDOR, classified as CWE-639.

Affected Systems

MervinPraison’s PraisonAI Platform versions earlier than 0.1.4 are affected. The issue is present across all project CRUD API endpoints that use a project identifier within a workspace context.

Risk and Exploitability

The CVSS score is 8.1, indicating high severity, while the EPSS score is below 1%, suggesting low current exploitation probability. The vulnerability is not yet listed in CISA’s KEV catalog. A user who can authenticate to any workspace can exploit the flaw by calling the affected APIs with a project identifier from another workspace, bypassing authorization. No active exploit has been reported publicly.

Generated by OpenCVE AI on July 30, 2026 at 16:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PraisonAI Platform to version 0.1.4 or later to apply the fix that enforces workspace ownership checks on all project operations.
  • If an upgrade is temporarily infeasible, modify the API layer to forward the workspace identifier into every project lookup, update, delete, or statistics function, ensuring that the project is verified to belong to the requester’s workspace before performing the operation.
  • Continuously monitor API logs for cross‑workspace project access patterns and trigger alerts when a project identifier does not match the requester’s workspace until the patch or code change is deployed.

Generated by OpenCVE AI on July 30, 2026 at 16:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-943m-6wx2-rc2j praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR
History

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The project CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/projects/{project_id}` and `GET .../{project_id}/stats`) gate access on `require_workspace_member(workspace_id)` only, then resolve `project_id` through `ProjectService.get(project_id)` / `update(project_id, ...)` / `delete(project_id)` / `get_stats(project_id)`. None of these calls thread `workspace_id` through to constrain the lookup. A user who is a member of any workspace `W1` can read, modify, delete, or read stats for projects that belong to a different workspace `W2`. PraisonAI Platform version 0.1.4 patches the issue.
Title praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Mervinpraison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-22T18:27:07.254Z

Reserved: 2026-05-19T19:37:43.526Z

Link: CVE-2026-47418

cve-icon Vulnrichment

Updated: 2026-07-22T18:06:47.199Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:00:07Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key