Insecure Direct Object Reference in PraisonAI Platform Affects User Access Control
CVE-2026-47414

7.6HIGH

Key Information:

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47414?

The PraisonAI Platform suffers from an Insecure Direct Object Reference vulnerability, primarily affecting versions prior to 0.1.4. This flaw permits unauthorized access to sensitive resources by not adequately validating label_id and issue_id against the user's workspace. Five API endpoints, including those for updating and deleting labels associated with workspaces and issues, fail to enforce proper access checks, potentially exposing users to data leaks or manipulation. Version 0.1.4 of the platform addresses this crucial issue.

Affected Version(s)

praisonai-platform < 0.1.4

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.