Description
PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. Attackers with workspace member privileges can exploit PATCH and POST/DELETE endpoints to alter shared label taxonomy and manipulate issue-label associations without owner or admin authorization.
Published: 2026-07-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

PraisonAI Platform before version 0.1.9 does not enforce proper authorization on label and issue-label mutations. Workspace members can use the PATCH, POST, and DELETE label endpoints to rename, recolor, and add or remove these labels from issues owned by other users. This flaw constitutes an authorization bypass (CWE‑862). The impact is the unauthorized modification of label taxonomy and issue‑label associations without owner or administrator approval.

Affected Systems

The affected product is the PraisonAI Platform from MervinPraison. Any instance running a release prior to 0.1.9 is vulnerable. Users of earlier versions can exercise the compromised label operations to alter shared labels and issue labels in their workspaces.

Risk and Exploitability

The vulnerability has a CVSS score of 7.1, indicating moderate severity. The EPSS score is reported as less than 1 %, suggesting a low probability of exploitation at the time of this analysis. The flaw is not listed in CISA’s KEV catalog. An attacker needs only workspace member privileges and network access to the API; no additional software or privilege escalation is required. The attack vector is remote over HTTP, using standard PATCH, POST, or DELETE requests to label endpoints.

Generated by OpenCVE AI on August 1, 2026 at 08:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the PraisonAI Platform to version 0.1.9 or newer, which introduces proper authorization checks for label operations.
  • If a version upgrade cannot be applied immediately, temporarily disable or restrict the PATCH, POST, and DELETE endpoints that manage labels for non‑owner users.
  • Review and tighten role‑based permissions so that only owners or administrators can modify label definitions or issue‑label associations.

Generated by OpenCVE AI on August 1, 2026 at 08:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Mervinpraison
Mervinpraison praisonai
Vendors & Products Mervinpraison
Mervinpraison praisonai

Wed, 15 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Description PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. Attackers with workspace member privileges can exploit PATCH and POST/DELETE endpoints to alter shared label taxonomy and manipulate issue-label associations without owner or admin authorization.
Title PraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints
First Time appeared Praison
Praison praisonai
Weaknesses CWE-862
CPEs cpe:2.3:a:praison:praisonai:*:*:*:*:*:*:*:*
Vendors & Products Praison
Praison praisonai
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Mervinpraison Praisonai
Praison Praisonai
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-18T01:01:50.264Z

Reserved: 2026-07-09T14:05:47.928Z

Link: CVE-2026-61440

cve-icon Vulnrichment

Updated: 2026-07-18T01:00:54.828Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:00:04Z

Weaknesses