Privilege Escalation in PraisonAI Platform Affects Multi-Agent Teams System
CVE-2026-47413
9.6CRITICAL
What is CVE-2026-47413?
The PraisonAI Platform, which facilitates collaborative multi-agent teams, is susceptible to a privilege escalation vulnerability that allows a user with minimal permissions to inject any member into a workspace. This flaw arises from inadequate permission checks in the system's member management feature, particularly the POST /workspaces/{workspace_id}/members endpoint. The implementation fails to validate the user's access rights correctly, enabling unauthorized addition of members with elevated roles. To mitigate this vulnerability, it is essential to upgrade to version 0.1.4, which addresses the issue by implementing strict caller-permission checks.
Affected Version(s)
praisonai-platform < 0.1.4
