Access Control Flaw in PraisonAI Platform by PraisonAI
CVE-2026-47407
What is CVE-2026-47407?
The PraisonAI Platform has a critical configuration flaw in its access control mechanisms that permits malicious actors to exploit workspace identifiers and UUIDs to gain unauthorized access to resources of other workspaces. This occurs through an insufficient validation of resource IDs in conjunction with the workspace ID in URL paths, allowing users to interact with resources outside of their intended scope. Furthermore, inherent deficiencies in role management enable lower-tier members to elevate their privileges, modifying roles and manipulating workspace memberships without appropriate checks. The platform, which lacks adequate registrational safeguards such as email verification and exposes sensitive endpoints by default, requires immediate attention to fortify its security posture against such vulnerabilities. This issue has been addressed in version 0.1.4.
Affected Version(s)
praisonai-platform < 0.1.4
