Impact
PraisonAI Platform versions earlier than 0.1.9 allow a workspace member to delete issue dependencies that were originally created by an owner. The delete‑dependency API inspects the permissions only against the caller‑selected issue URL; if the member points the request to their own issue, the permission check succeeds even though the member has no rights on the dependency edge. This flaw enables an internal user to remove owner‑created relationships, undermining integrity and disrupting collaboration workflows, and corresponds to CWE‑862.
Affected Systems
The vulnerability affects all builds of the MervinPraison PraisionAI Platform released before version 0.1.9. Any installation running a version lower than 0.1.9 is susceptible; no further sub‑version details are provided.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1 % reflects a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is an authenticated internal user who can invoke the delete dependency API; such a member can remove dependencies that should be protected, potentially tampering with issue tracking data and audit trails. Overall risk remains high for environments that rely on strict owner control of dependencies.
OpenCVE Enrichment