Insecure Direct Object Reference in PraisonAI Platform
CVE-2026-47408
6.5MEDIUM
What is CVE-2026-47408?
The PraisonAI Platform, utilized for managing multi-agent teams, has a vulnerability related to Insecure Direct Object Reference. Specifically, the GET /workspaces/{workspace_id}/issues/{issue_id}/activity endpoint allows members from any workspace to access the complete activity log of issues within the environment, circumventing workspace constraints. This flaw arises from a lack of proper restrictions in the SQL query execution, enabling unauthorized data access. The vulnerability has been addressed in version 0.1.4, which restricts activity log access to authorized workspace members only.
Affected Version(s)
praisonai-platform < 0.1.4
