Praisonai-platform
This hub aggregates every CVE we track for Praisonai-platform, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
16
CVEs tracked
3
Critical
11
High
0
In CISA KEV
Severity distribution
HIGH11CRITICAL3MEDIUM2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
15
1
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Praisonai-platform.
- CVE-2026-48169PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API8.8
- CVE-2026-47419praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR8.3
- CVE-2026-47418praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR8.1
- CVE-2026-47417praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR8.1
- CVE-2026-47416praisonai-platform: Any workspace member can promote themselves (or any other member) to owner via PATCH /workspaces/{id}/members/{user_id}9.6
- CVE-2026-47415praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR8.3
- CVE-2026-47414praisonai-platform: Label endpoints accept any label_id and any issue_id without workspace ownership check, cross-workspace label edit/delete and issue-label-link IDOR7.6
- CVE-2026-47413praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members9.6
- CVE-2026-47412praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}8.1
- CVE-2026-47411praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}6.5
- CVE-2026-47410praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset9.8
- CVE-2026-47409praisonai-platform: Any workspace member can remove any other member (including the owner) via DELETE /workspaces/{id}/members/{user_id}8.1
- CVE-2026-47408praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership6.5
- CVE-2026-47406praisonai-platform: Dependency endpoints accept any issue_id and dep_id without workspace ownership check, cross-workspace issue linking + read + delete IDOR8.1
- CVE-2026-47405PraisonAI Platform missing role checks let any workspace member become owner and take over workspace membership8.8
Product normalization is registry-driven with AI assist and human review. How it works