Impact
PraisonAI Platform before version 0.1.9 does not enforce proper authorization on label and issue-label mutations. Workspace members can use the PATCH, POST, and DELETE label endpoints to rename, recolor, and add or remove these labels from issues owned by other users. This flaw constitutes an authorization bypass (CWE‑862). The impact is the unauthorized modification of label taxonomy and issue‑label associations without owner or administrator approval.
Affected Systems
The affected product is the PraisonAI Platform from MervinPraison. Any instance running a release prior to 0.1.9 is vulnerable. Users of earlier versions can exercise the compromised label operations to alter shared labels and issue labels in their workspaces.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating moderate severity. The EPSS score is reported as less than 1 %, suggesting a low probability of exploitation at the time of this analysis. The flaw is not listed in CISA’s KEV catalog. An attacker needs only workspace member privileges and network access to the API; no additional software or privilege escalation is required. The attack vector is remote over HTTP, using standard PATCH, POST, or DELETE requests to label endpoints.
OpenCVE Enrichment