Mervinpraison Praisonai-Platform vulnerabilities
19 known vulnerabilities affecting mervinpraison/praisonai-platform.
Total CVEs
19
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH11MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-57147P2CRITICALCVSS 9.8fixed in 0.1.62026-09-15
CVE-2026-57147 [CRITICAL] CWE-798 CVE-2026-57147: PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py
PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run when PLATFORM_ENV is also unset because that setting defaults to dev. A remote unauthenticated attacker can mint an
nvd
CVE-2026-57148P2CRITICALCVSS 9.8fixed in 0.1.62026-09-15
CVE-2026-57148 [CRITICAL] CWE-287 CVE-2026-57148: PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py
PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup and token-issuance guards are disabled because PLATFORM_ENV also defaults to dev. An unauthenticated attacker can sign a JWT contai
nvd
CVE-2026-47405P2HIGHCVSS 8.8fixed in 0.1.42026-07-21
CVE-2026-47405 [HIGH] CWE-284 CVE-2026-47405: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization check that allows any authenticated low-privilege workspace member to escalate their own role to `owner`. The issue is caused by privileged workspace-management routes using the shared dependency `require_wo
nvd
CVE-2026-47410P2CRITICALCVSS 9.8fixed in 0.1.42026-07-21
CVE-2026-47410 [CRITICAL] CWE-321 CVE-2026-47410: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcoded literal `"dev-secret-change-me"` when `PLATFORM_JWT_SECRET` is unset. A safety check exists but only fires when `PLATFORM_ENV != "dev"`; the default
nvd
CVE-2026-47413P2CRITICALCVSS 9.6fixed in 0.1.42026-07-21
CVE-2026-47413 [CRITICAL] CWE-269 CVE-2026-47413: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST /workspaces/{workspace_id}/members` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`) and forwards the request body's `user_
nvd
CVE-2026-47416P2CRITICALCVSS 9.6fixed in 0.1.42026-07-21
CVE-2026-47416 [CRITICAL] CWE-269 CVE-2026-47416: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` endpoint is gated by `require_workspace_member(workspace_id)`, which defaults to `min_role="member"` and is never overridden by the rou
nvd
CVE-2026-48169P3HIGHCVSS 8.8fixed in 0.1.42026-08-07
CVE-2026-48169 [HIGH] CWE-639 CVE-2026-48169: PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have
PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key lookups without checking workspace ownership, so any authenticated user can read, modify, and delete resources in an
nvd
CVE-2026-47399P3HIGHCVSS 8.8fixed in 0.1.42026-07-21
CVE-2026-47399 [HIGH] CWE-284 CVE-2026-47399: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to versio
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization flaw that allows an authenticated user from one workspace to access, modify, and delete objects belonging to another workspace by supplying the victim object's globa
nvd
CVE-2026-47407P3CRITICALCVSS 9.4fixed in 0.1.42026-07-21
CVE-2026-47407 [CRITICAL] CWE-269 CVE-2026-47407: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to versio
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces/{workspace_id}/...` and protects them with a `require_workspace_member(workspace_id)` FastAPI dependency. The dependency only checks that the caller is a member of the workspac
nvd
CVE-2026-47419P3HIGHCVSS 8.3fixed in 0.1.42026-07-21
CVE-2026-47419 [HIGH] CWE-639 CVE-2026-47419: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* Insecure Direct Object Reference. The agent CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/agents/{agent_id}`) gate access on `require_workspace_member(workspace_id)` only, then resolve `agent_id` through `AgentService
nvd
CVE-2026-47415P3HIGHCVSS 8.3fixed in 0.1.42026-07-21
CVE-2026-47415 [HIGH] CWE-639 CVE-2026-47415: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The issue CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/issues/{issue_id}`) gate access on `require_workspace_member(workspace_id)` only, then resolve `issue_id` through `IssueService.
nvd
CVE-2026-47406P3HIGHCVSS 8.1fixed in 0.1.42026-07-21
CVE-2026-47406 [HIGH] CWE-639 CVE-2026-47406: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The dependency endpoints (`POST/GET /workspaces/{workspace_id}/issues/{issue_id}/dependencies` and `DELETE .../dependencies/{dep_id}`) gate access on `require_workspace_member(workspace_id)` only, then d
nvd
CVE-2026-47418P3HIGHCVSS 8.1fixed in 0.1.42026-07-21
CVE-2026-47418 [HIGH] CWE-639 CVE-2026-47418: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The project CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/projects/{project_id}` and `GET .../{project_id}/stats`) gate access on `require_workspace_member(workspace_id)` only, then re
nvd
CVE-2026-47417P3HIGHCVSS 8.1fixed in 0.1.42026-07-21
CVE-2026-47417 [HIGH] CWE-639 CVE-2026-47417: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The comment endpoints (`POST /workspaces/{workspace_id}/issues/{issue_id}/comments` and `GET .../comments`) gate access on `require_workspace_member(workspace_id)` only, then call `CommentService.create(
nvd
CVE-2026-47409P3HIGHCVSS 8.1fixed in 0.1.42026-07-21
CVE-2026-47409 [HIGH] CWE-269 CVE-2026-47409: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling owner lockout. The `DELETE /workspaces/{workspace_id}/members/{user_id}` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`). Any member can remove any other memb
nvd
CVE-2026-47412P3HIGHCVSS 8.1fixed in 0.1.42026-07-21
CVE-2026-47412 [HIGH] CWE-269 CVE-2026-47412: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE /workspaces/{workspace_id}` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`). Any member of the workspace can issue a single DE
nvd
CVE-2026-47414P3HIGHCVSS 7.6fixed in 0.1.42026-07-21
CVE-2026-47414 [HIGH] CWE-639 CVE-2026-47414: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. Five label endpoints — `PATCH /workspaces/{workspace_id}/labels/{label_id}`, `DELETE .../labels/{label_id}`, `POST .../issues/{issue_id}/labels/{label_id}`, `DELETE .../issues/{issue_id}/labels/{label_id
nvd
CVE-2026-47411P3MEDIUMCVSS 6.5fixed in 0.1.42026-07-21
CVE-2026-47411 [MEDIUM] CWE-269 CVE-2026-47411: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling workspace metadata + settings tampering. The `PATCH /workspaces/{workspace_id}` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`). Any member can rewrite the
nvd
CVE-2026-47408P3MEDIUMCVSS 6.5fixed in 0.1.42026-07-21
CVE-2026-47408 [MEDIUM] CWE-639 CVE-2026-47408: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The `GET /workspaces/{workspace_id}/issues/{issue_id}/activity` endpoint is gated by `require_workspace_member(workspace_id)` and dispatches to `ActivityService.list_for_issue(issue_id)`, which execute
nvd