CVE-2026-47417: CWE-639: Authorization Bypass Through User-Controlled Key in MervinPraison praisonai-platform
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The comment endpoints (`POST /workspaces/{workspace_id}/issues/{issue_id}/comments` and `GET .../comments`) gate access on `require_workspace_member(workspace_id)` only, then call `CommentService.create(issue_id=issue_id, ...)` and `CommentService.list_for_issue(issue_id)` without verifying that `issue_id` belongs to `workspace_id`. A user who is a member of any workspace `W1` can read every comment on, and post new comments to, any issue in any other workspace `W2`. PraisonAI Platform version 0.1.4 patches the issue.
AI Analysis
Technical Summary
The PraisonAI Platform's comment endpoints (`POST /workspaces/{workspace_id}/issues/{issue_id}/comments` and `GET .../comments`) enforce access control only by verifying that a user is a member of the specified workspace. However, they fail to verify that the `issue_id` actually belongs to that workspace. This allows a user who is a member of one workspace to access and manipulate comments on issues in other workspaces, resulting in an Insecure Direct Object Reference (CWE-639). The vulnerability affects all versions prior to 0.1.4, which includes the affected versions identified. The issue is patched in version 0.1.4.
Potential Impact
An attacker who is a member of any workspace can bypass authorization controls to read and post comments on issues in other workspaces. This leads to unauthorized disclosure and modification of comments, impacting confidentiality and integrity. Availability is not affected. The CVSS v3.1 score is 8.1 (High), reflecting network attack vector, low complexity, requiring privileges, no user interaction, unchanged scope, and high confidentiality and integrity impact.
Mitigation Recommendations
Upgrade to PraisonAI Platform version 0.1.4 or later, where the issue is fixed by properly verifying that the issue belongs to the workspace before allowing comment access or creation. No other mitigations are documented. Patch status is not explicitly stated in vendor advisory content, but the description confirms version 0.1.4 contains the fix.
CVE-2026-47417: CWE-639: Authorization Bypass Through User-Controlled Key in MervinPraison praisonai-platform
Description
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The comment endpoints (`POST /workspaces/{workspace_id}/issues/{issue_id}/comments` and `GET .../comments`) gate access on `require_workspace_member(workspace_id)` only, then call `CommentService.create(issue_id=issue_id, ...)` and `CommentService.list_for_issue(issue_id)` without verifying that `issue_id` belongs to `workspace_id`. A user who is a member of any workspace `W1` can read every comment on, and post new comments to, any issue in any other workspace `W2`. PraisonAI Platform version 0.1.4 patches the issue.
CVSS v3.1
Score 8.1high
Affected software
pkg:github/mervinpraison/praisonai-platformRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The PraisonAI Platform's comment endpoints (`POST /workspaces/{workspace_id}/issues/{issue_id}/comments` and `GET .../comments`) enforce access control only by verifying that a user is a member of the specified workspace. However, they fail to verify that the `issue_id` actually belongs to that workspace. This allows a user who is a member of one workspace to access and manipulate comments on issues in other workspaces, resulting in an Insecure Direct Object Reference (CWE-639). The vulnerability affects all versions prior to 0.1.4, which includes the affected versions identified. The issue is patched in version 0.1.4.
Potential Impact
An attacker who is a member of any workspace can bypass authorization controls to read and post comments on issues in other workspaces. This leads to unauthorized disclosure and modification of comments, impacting confidentiality and integrity. Availability is not affected. The CVSS v3.1 score is 8.1 (High), reflecting network attack vector, low complexity, requiring privileges, no user interaction, unchanged scope, and high confidentiality and integrity impact.
Mitigation Recommendations
Upgrade to PraisonAI Platform version 0.1.4 or later, where the issue is fixed by properly verifying that the issue belongs to the workspace before allowing comment access or creation. No other mitigations are documented. Patch status is not explicitly stated in vendor advisory content, but the description confirms version 0.1.4 contains the fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-19T19:37:43.526Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a5faf7e2a4a8d5989832bcd
Added to database: 07/21/2026, 17:42:22 UTC
Last enriched: 07/21/2026, 17:56:53 UTC
Last updated: 07/21/2026, 21:11:11 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.