Impact
PraisonAI Platform before version 0.1.9 does not enforce owner or admin permissions on the PATCH endpoints for projects, issues, and agents, requiring only a workspace‑member role. This flaw allows a non‑owner user to modify records created by the owner, reassign project lead identifiers, and subsequently delete the project, effectively bypassing the deletion route’s owner/admin check. The result is loss of ownership integrity and potential data loss or unauthorized configuration changes, as described in the CWE-862 “Missing Authorization” weakness.
Affected Systems
MervinPraison PraisonAI Platform, all releases earlier than version 0.1.9 (including 0.1.8 and lower).
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score is < 1%. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely through authenticated web API requests; an attacker only needs a workspace member role and the ability to send PATCH requests to the vulnerable routes.
OpenCVE Enrichment