Object-Level Authorization Flaw in PraisonAI Platform Affects Workspace Data Security
CVE-2026-47399
8.8HIGH
What is CVE-2026-47399?
The PraisonAI Platform suffers from an object-level authorization flaw that allows authenticated users to access and manipulate data across different workspaces. Specifically, prior to version 0.1.4, the platform's workspace-scoped REST routes did not enforce proper isolation checks. This design flaw enabled users to bypass workspace boundaries by utilizing the global UUID of objects belonging to other workspaces. As such, a member of one workspace could exploit this vulnerability to perform unauthorized operations on items from another workspace, leading to potential data breaches and unauthorized modifications.
Affected Version(s)
praisonai-platform < 0.1.4
