Impact
PraisonAI Platform versions before 0.1.9 allow a workspace member who lacks deletion rights on an owner-created dependency to remove that dependency by targeting a user-owned endpoint. The DELETE dependency endpoint verifies permission only against the selected issue URL, so if a member points the request to their own issue, the check succeeds even though they have no rights on the dependency itself. This flaw lets internal users alter issue-tracking relationships, compromising data integrity and audit trails, and corresponds to CWE-862.
Affected Systems
The vulnerability affects all installations of the MervinPraison PraisonAI Platform released before version 0.1.9. Any build lower than 0.1.9 is vulnerable; no finer sub-version details are provided in the advisory.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% reflects a very low but non-zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The description shows that the attack vector requires an authenticated internal user with workspace membership who can invoke the delete-dependency API, making the exploit relatively easy in compromised or untrustworthy workspaces. The resulting integrity loss can undermine collaboration and audit processes, so the overall risk remains high for organizations relying on strict owner control of dependencies.
OpenCVE Enrichment