CVE-2026-47416: CWE-269: Improper Privilege Management in MervinPraison praisonai-platform
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` endpoint is gated by `require_workspace_member(workspace_id)`, which defaults to `min_role="member"` and is never overridden by the route. The handler then calls `MemberService.update_role(workspace_id, user_id, body.role)` which sets the target member's role to whatever the request body specifies, with no check that the caller has owner-or-admin privilege, no check that the new role is not higher than the caller's own, and no check that the caller is not silently promoting themselves. PraisonAI Platform version 0.1.4 patches the issue.
AI Analysis
Technical Summary
The PraisonAI Platform's PATCH /workspaces/{workspace_id}/members/{user_id} endpoint is protected by a check requiring the caller to be at least a workspace member, but this check does not enforce stricter role requirements. The endpoint handler calls MemberService.update_role to set the target user's role based solely on the request body, without verifying that the caller has owner or admin privileges, or that the new role is not higher than the caller's own role. This flaw enables vertical privilege escalation by allowing unauthorized role changes, including self-promotion. The vulnerability affects all versions prior to 0.1.4, which includes the fix.
Potential Impact
An attacker with member-level access to a workspace can escalate their privileges to owner or admin roles without authorization. This results in a complete compromise of workspace access control, allowing unauthorized access to sensitive data and administrative functions. The vulnerability has a CVSS 3.1 base score of 9.6 (critical), indicating high impact on confidentiality and integrity with no impact on availability.
Mitigation Recommendations
Upgrade to PraisonAI Platform version 0.1.4 or later, which patches the privilege escalation vulnerability by enforcing proper role checks on the PATCH /workspaces/{workspace_id}/members/{user_id} endpoint. Since no official remediation level or patch link is provided, verify the upgrade from the vendor's official release notes or repository. Until patched, restrict access to the affected endpoint to trusted users only, if possible.
CVE-2026-47416: CWE-269: Improper Privilege Management in MervinPraison praisonai-platform
Description
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` endpoint is gated by `require_workspace_member(workspace_id)`, which defaults to `min_role="member"` and is never overridden by the route. The handler then calls `MemberService.update_role(workspace_id, user_id, body.role)` which sets the target member's role to whatever the request body specifies, with no check that the caller has owner-or-admin privilege, no check that the new role is not higher than the caller's own, and no check that the caller is not silently promoting themselves. PraisonAI Platform version 0.1.4 patches the issue.
CVSS v3.1
Score 9.6critical
Affected software
pkg:github/mervinpraison/praisonai-platformRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The PraisonAI Platform's PATCH /workspaces/{workspace_id}/members/{user_id} endpoint is protected by a check requiring the caller to be at least a workspace member, but this check does not enforce stricter role requirements. The endpoint handler calls MemberService.update_role to set the target user's role based solely on the request body, without verifying that the caller has owner or admin privileges, or that the new role is not higher than the caller's own role. This flaw enables vertical privilege escalation by allowing unauthorized role changes, including self-promotion. The vulnerability affects all versions prior to 0.1.4, which includes the fix.
Potential Impact
An attacker with member-level access to a workspace can escalate their privileges to owner or admin roles without authorization. This results in a complete compromise of workspace access control, allowing unauthorized access to sensitive data and administrative functions. The vulnerability has a CVSS 3.1 base score of 9.6 (critical), indicating high impact on confidentiality and integrity with no impact on availability.
Mitigation Recommendations
Upgrade to PraisonAI Platform version 0.1.4 or later, which patches the privilege escalation vulnerability by enforcing proper role checks on the PATCH /workspaces/{workspace_id}/members/{user_id} endpoint. Since no official remediation level or patch link is provided, verify the upgrade from the vendor's official release notes or repository. Until patched, restrict access to the affected endpoint to trusted users only, if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-19T19:37:43.526Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5faf7e2a4a8d5989832bc9
Added to database: 07/21/2026, 17:42:22 UTC
Last enriched: 07/21/2026, 17:56:59 UTC
Last updated: 07/21/2026, 21:11:25 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.