What happened
NVD published CVE-2026-62179 (CVSS 6.5) on 2026-10-07 for an authorization mismatch in praisonai-platform < 0.1.9: dependency deletion can be authorized against the wrong side of a dependency edge, and a workspace member can delete a dependency that the owner-created issue endpoint should not permit them to remove.
Why it matters
A broken object-level authorization in a multi-agent collaboration platform: the boundary between workspace member roles is mis-enforced on delete operations, enabling cross-permission data destruction in team agent deployments — low blast radius but a precise authz defect in the same framework that produced two RCEs this week.
Attack vector
An authenticated workspace member submits a delete through the issue/dependency API whose authorization check is applied to the wrong side of a dependency edge, letting the member delete a dependency via an owner-created issue endpoint they could not normally reach — an authorization bypass for object deletion.
Affected systems
praisonai-platform prior to 0.1.9 (GHSA-mxmx-rh57-jx58)
Mitigation
Upgrade praisonai-platform to 0.1.9 or later (GitHub Security Advisory GHSA-mxmx-rh57-jx58).