Privilege Escalation in PraisonAI Platform Affects Multi-Agent Teams System
CVE-2026-47413

9.6CRITICAL

Key Information:

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47413?

The PraisonAI Platform, which facilitates collaborative multi-agent teams, is susceptible to a privilege escalation vulnerability that allows a user with minimal permissions to inject any member into a workspace. This flaw arises from inadequate permission checks in the system's member management feature, particularly the POST /workspaces/{workspace_id}/members endpoint. The implementation fails to validate the user's access rights correctly, enabling unauthorized addition of members with elevated roles. To mitigate this vulnerability, it is essential to upgrade to version 0.1.4, which addresses the issue by implementing strict caller-permission checks.

Affected Version(s)

praisonai-platform < 0.1.4

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.