Vulnerability  ·  2026-10-09

PraisonAI platform: workspace member can delete dependency-issue content via an authorization gap

VulnerabilityLow impactGlobalCVE-2026-62179
NVD published CVE-2026-62179 (CVSS 6.5) on 2026-10-07 for an authorization mismatch in praisonai-platform < 0.1.9: dependency deletion can be authorized against the wrong side of a dependency edge, and a workspace member can delete a dependency that the owner-created issue endpoint should not permit them to remove.
A broken object-level authorization in a multi-agent collaboration platform: the boundary between workspace member roles is mis-enforced on delete operations, enabling cross-permission data destruction in team agent deployments — low blast radius but a precise authz defect in the same framework that produced two RCEs this week.
An authenticated workspace member submits a delete through the issue/dependency API whose authorization check is applied to the wrong side of a dependency edge, letting the member delete a dependency via an owner-created issue endpoint they could not normally reach — an authorization bypass for object deletion.
praisonai-platform prior to 0.1.9 (GHSA-mxmx-rh57-jx58)
Upgrade praisonai-platform to 0.1.9 or later (GitHub Security Advisory GHSA-mxmx-rh57-jx58).
GitHub Security Advisory GHSA-mxmx-rh57-jx58NVD entry
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →