Insecure Direct Object Reference in PraisonAI Platform
CVE-2026-47408

6.5MEDIUM

Key Information:

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47408?

The PraisonAI Platform, utilized for managing multi-agent teams, has a vulnerability related to Insecure Direct Object Reference. Specifically, the GET /workspaces/{workspace_id}/issues/{issue_id}/activity endpoint allows members from any workspace to access the complete activity log of issues within the environment, circumventing workspace constraints. This flaw arises from a lack of proper restrictions in the SQL query execution, enabling unauthorized data access. The vulnerability has been addressed in version 0.1.4, which restricts activity log access to authorized workspace members only.

Affected Version(s)

praisonai-platform < 0.1.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.