praisonai-platform
PyPI18 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting praisonai-platformpage 1 of 1
- CVE-2026-47399HIGHCVSS 8.8EG 8.8✓ Fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization flaw that allows an authenticated user from one wor…
- CVE-2026-47405HIGHCVSS 8.8EG 8.8✓ Fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization check that allows any authenticated low-privilege workspace member to escalate their own rol…
- CVE-2026-47406HIGHCVSS 8.1EG 8.1✓ Fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The dependency endpoints (`POST/GET /workspaces/{workspace_id}/issues/{issue_id}/depende…
- CVE-2026-47407CRITICALCVSS 9.4EG 9.4✓ Fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces/{workspace_id}/...` and protects them with a `require_workspace_me…
- CVE-2026-47408MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The `GET /workspaces/{workspace_id}/issues/{issue_id}/activity` endpoint is gated by `re…
- CVE-2026-47409HIGHCVSS 8.1EG 8.1✓ Fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling owner lockout. The `DELETE /workspaces/{workspace_id}/members/{user_id}` endpoint is gated o…
- CVE-2026-47410CRITICALCVSS 9.8EG 9.8✓ Fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcoded literal `"dev-secret-change-me"` when…
- CVE-2026-47411MEDIUMCVSS 6.5EG 6.5✓ Fixed in 0.1.42026-06-01
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling workspace metadata + settings tampering. The `PATCH /workspaces/{workspace_id}` endpoint is …
- CVE-2026-47412HIGHCVSS 8.1EG 8.1✓ Fixed in 0.1.42026-06-01
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE /workspaces/{workspace_id}` endpoint is gated only by `requi…
- CVE-2026-47413CRITICALCVSS 9.6EG 9.6✓ Fixed in 0.1.42026-06-01
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST /workspaces/{workspace_id}/members` endpoint is gated only b…
- CVE-2026-47414HIGHCVSS 7.6EG 7.6✓ Fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. Five label endpoints — `PATCH /workspaces/{workspace_id}/labels/{label_id}`, `DELETE .…
- CVE-2026-47415HIGHCVSS 8.3EG 8.3✓ Fixed in 0.1.42026-06-01
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The issue CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/issues/{issue…
- CVE-2026-47416CRITICALCVSS 9.6EG 9.6✓ Fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` endpoint is gated by `re…
- CVE-2026-47417HIGHCVSS 8.1EG 8.1✓ Fixed in 0.1.42026-06-01
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The comment endpoints (`POST /workspaces/{workspace_id}/issues/{issue_id}/comments` and …
- CVE-2026-47418HIGHCVSS 8.1EG 8.1✓ Fixed in 0.1.42026-06-01
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The project CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/projects/{p…
- CVE-2026-47419HIGHCVSS 8.3EG 8.3✓ Fixed in 0.1.42026-06-05
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* Insecure Direct Object Reference. The agent CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/agents/{agen…
- CVE-2026-48169HIGHCVSS 8.8EG 8.8✓ Fixed in 0.1.42026-05-29
vulnerable: 0.1.0, 0.1.1, 0.1.2, 0.1.3
PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API ### Summary The PraisonAI Platform API has two authorization failures that together break workspace isolation. The service layer for issues and projects perform…
- CVE-2026-58653MEDIUMCVSS 4.3EG 4.3✓ Fixed in 0.1.82026-07-02
vulnerable: 0.1.0 ... 0.1.6 (6 versions)
PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL workspace. An attacker can create issues referencing projects from other workspaces, causing cross-tenant data pollution …
Check whether praisonai-platform is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for praisonai-platform CVEs against the assets you own.
Start Free Scan →