CVE-2026-48169
published 2026-08-07CVE-2026-48169: PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace…
PriorityP358high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.44%
36.0th percentile
PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups without checking workspace ownership, so any authenticated user can read, modify, and delete resources in any workspace just by swapping UUIDs in their API requests. On top of that, every member management endpoint (add, update role, remove) only requires `min_role="member"`, which lets any workspace member promote themselves to owner and kick out the original owner. A low-privilege member of one workspace can steal data from every other workspace and take over any workspace they belong to. Both issues come from the same gap: the route layer pulls `workspace_id` from the URL and verifies membership, but the service layer ignores the workspace scope for resource lookups and ignores the caller's role level for member operations. The `require_workspace_member()` dependency does its job correctly. The problem is that the service layer doesn't use the information it provides. Version 0.1.4 of the PraisonAI Platform API patch the issue.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mervinpraison | praisonai-platform | < 0.1.4 | 0.1.4 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
MervinPraison PraisonAI Platform up to 0.1.3 Service Layer workspace_id improper authorization
vuldb·2026-08-07·CVSS 8.8
CVE-2026-48169 [HIGH] MervinPraison PraisonAI Platform up to 0.1.3 Service Layer workspace_id improper authorization
A vulnerability was found in MervinPraison PraisonAI Platform up to 0.1.3. It has been rated as critical. This impacts an unknown function of the component Service Layer. This manipulation of the argument workspace_id causes improper authorization.
This vulnerability is handled as CVE-2026-48169. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
GHSA
PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API
ghsa·2026-05-29
CVE-2026-48169 [HIGH] CWE-639 PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API
PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API
### Summary
The PraisonAI Platform API has two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups without checking workspace ownership, so any authenticated user can read, modify, and delete resources in any workspace just by swapping UUIDs in their API requests. On top of that, every member management endpoint (add, update role, remove) only requires `min_role="member"`, which lets any workspace member promote themselves to owner and kick out the original owner. A low-privilege member of one workspace can steal data from every other workspace and take over any workspace they belong to.
Both issues come from the same gap:
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-07
Published