CVE-2026-48169: CWE-639: Authorization Bypass Through User-Controlled Key in MervinPraison praisonai-platform
CVE-2026-48169 affects the PraisonAI Platform API versions prior to 0.1.4 and involves authorization bypass vulnerabilities that break workspace isolation. The service layer performs global primary-key lookups without verifying workspace ownership, allowing authenticated users to access resources across workspaces by manipulating UUIDs. Additionally, member management endpoints require only minimal role checks, enabling members to escalate their privileges to owner and remove original owners. These combined flaws allow low-privilege members to steal data and take over any workspace they belong to. Version 0.1.4 of the PraisonAI Platform API addresses these issues.
AI Analysis
Technical Summary
The PraisonAI Platform API prior to version 0.1.4 contains two critical authorization failures. First, the service layer for issues and projects performs global primary-key lookups without validating workspace ownership, enabling any authenticated user to read, modify, or delete resources in any workspace by swapping UUIDs in API requests. Second, member management endpoints (add, update role, remove) only require a minimum role of "member", allowing any workspace member to promote themselves to owner and remove the original owner. The root cause is that while the route layer verifies workspace membership via the workspace_id in the URL, the service layer ignores workspace scope and caller role level during resource lookups and member operations. The require_workspace_member() dependency functions correctly, but the service layer does not utilize its output properly. These vulnerabilities break workspace isolation and allow unauthorized data access and privilege escalation. The issues are fixed in version 0.1.4 of the PraisonAI Platform API.
Potential Impact
An attacker with low-privilege membership in any workspace can exploit these vulnerabilities to access, modify, or delete resources in any workspace by manipulating resource identifiers. They can also escalate their privileges to owner in any workspace they belong to and remove the original owner, effectively taking over the workspace. This results in a complete breach of workspace isolation, leading to high confidentiality, integrity, and availability impacts across all workspaces accessible to the attacker.
Mitigation Recommendations
Version 0.1.4 of the PraisonAI Platform API patches these authorization bypass issues. Users and administrators should upgrade to version 0.1.4 or later to remediate the vulnerabilities. No other mitigation steps are indicated by the vendor advisory.
CVE-2026-48169: CWE-639: Authorization Bypass Through User-Controlled Key in MervinPraison praisonai-platform
Description
CVE-2026-48169 affects the PraisonAI Platform API versions prior to 0.1.4 and involves authorization bypass vulnerabilities that break workspace isolation. The service layer performs global primary-key lookups without verifying workspace ownership, allowing authenticated users to access resources across workspaces by manipulating UUIDs. Additionally, member management endpoints require only minimal role checks, enabling members to escalate their privileges to owner and remove original owners. These combined flaws allow low-privilege members to steal data and take over any workspace they belong to. Version 0.1.4 of the PraisonAI Platform API addresses these issues.
CVSS v3.1
Score 8.8high
Affected software
pkg:github/mervinpraison/praisonai-platformRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The PraisonAI Platform API prior to version 0.1.4 contains two critical authorization failures. First, the service layer for issues and projects performs global primary-key lookups without validating workspace ownership, enabling any authenticated user to read, modify, or delete resources in any workspace by swapping UUIDs in API requests. Second, member management endpoints (add, update role, remove) only require a minimum role of "member", allowing any workspace member to promote themselves to owner and remove the original owner. The root cause is that while the route layer verifies workspace membership via the workspace_id in the URL, the service layer ignores workspace scope and caller role level during resource lookups and member operations. The require_workspace_member() dependency functions correctly, but the service layer does not utilize its output properly. These vulnerabilities break workspace isolation and allow unauthorized data access and privilege escalation. The issues are fixed in version 0.1.4 of the PraisonAI Platform API.
Potential Impact
An attacker with low-privilege membership in any workspace can exploit these vulnerabilities to access, modify, or delete resources in any workspace by manipulating resource identifiers. They can also escalate their privileges to owner in any workspace they belong to and remove the original owner, effectively taking over the workspace. This results in a complete breach of workspace isolation, leading to high confidentiality, integrity, and availability impacts across all workspaces accessible to the attacker.
Mitigation Recommendations
Version 0.1.4 of the PraisonAI Platform API patches these authorization bypass issues. Users and administrators should upgrade to version 0.1.4 or later to remediate the vulnerabilities. No other mitigation steps are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-20T23:12:43.033Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a76512cbf8831d5393521f4
Added to database: 08/07/2026, 21:42:04 UTC
Last enriched: 08/07/2026, 21:56:16 UTC
Last updated: 08/07/2026, 22:22:57 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.