praisonai-platform
PyPI21 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting praisonai-platformpage 1 of 1
- CVE-2026-47399HIGHCVSS 8.8EG 8.8fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization flaw that allows an authenticated user from one wor…
- CVE-2026-47405HIGHCVSS 8.8EG 8.8fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization check that allows any authenticated low-privilege workspace member to escalate their own rol…
- CVE-2026-47406HIGHCVSS 8.1EG 8.1fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The dependency endpoints (`POST/GET /workspaces/{workspace_id}/issues/{issue_id}/depende…
- CVE-2026-47407CRITICALCVSS 9.4EG 9.4fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces/{workspace_id}/...` and protects them with a `require_workspace_me…
- CVE-2026-47408MEDIUMCVSS 6.5EG 6.5fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The `GET /workspaces/{workspace_id}/issues/{issue_id}/activity` endpoint is gated by `re…
- CVE-2026-47409HIGHCVSS 8.1EG 8.1fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling owner lockout. The `DELETE /workspaces/{workspace_id}/members/{user_id}` endpoint is gated o…
- CVE-2026-47410CRITICALCVSS 9.8EG 9.8fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcoded literal `"dev-secret-change-me"` when…
- CVE-2026-47411MEDIUMCVSS 6.5EG 6.5fixed in 0.1.42026-06-01
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling workspace metadata + settings tampering. The `PATCH /workspaces/{workspace_id}` endpoint is …
- CVE-2026-47412HIGHCVSS 8.1EG 8.1fixed in 0.1.42026-06-01
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE /workspaces/{workspace_id}` endpoint is gated only by `requi…
- CVE-2026-47413CRITICALCVSS 9.6EG 9.6fixed in 0.1.42026-06-01
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST /workspaces/{workspace_id}/members` endpoint is gated only b…
- CVE-2026-47414HIGHCVSS 7.6EG 7.6fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. Five label endpoints — `PATCH /workspaces/{workspace_id}/labels/{label_id}`, `DELETE .…
- CVE-2026-47415HIGHCVSS 8.3EG 8.3fixed in 0.1.42026-06-01
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The issue CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/issues/{issue…
- CVE-2026-47416CRITICALCVSS 9.6EG 9.6fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` endpoint is gated by `re…
- CVE-2026-47417HIGHCVSS 8.1EG 8.1fixed in 0.1.42026-06-01
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The comment endpoints (`POST /workspaces/{workspace_id}/issues/{issue_id}/comments` and …
- CVE-2026-47418HIGHCVSS 8.1EG 8.1fixed in 0.1.42026-06-01
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The project CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/projects/{p…
- CVE-2026-47419HIGHCVSS 8.3EG 8.3fixed in 0.1.42026-06-05
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* Insecure Direct Object Reference. The agent CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/agents/{agen…
- CVE-2026-48169HIGHCVSS 8.8EG 8.8fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break workspace isolation. The service layer for issues and projects performs global primary-key l…
- CVE-2026-57121HIGHCVSS 8.1EG 8.1fixed in 0.1.62026-06-18
vulnerable: 0.1.4
PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API ### Summary A workspace member can permanently delete any resource — projects, agents, issues, labels, issue dependencies, a…
- CVE-2026-57147CRITICALCVSS 9.8EG 9.8fixed in 0.1.62026-06-18
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.1.4
PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run when …
- CVE-2026-57148CRITICALCVSS 9.8EG 9.8fixed in 0.1.62026-06-18
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.1.4
PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup and token-issuance gu…
- CVE-2026-58653MEDIUMCVSS 4.3EG 4.3fixed in 0.1.82026-07-02
vulnerable: 0.1.0 ... 0.1.6 (6 versions)
PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL workspace. An attacker can create issues referencing projects from other workspaces, causing cross-tenant data pollution …
Check whether praisonai-platform is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for praisonai-platform CVEs against the assets you own.
Book a Demo →