Insecure Direct Object Reference in PraisonAI Platform Affects User Access Control
CVE-2026-47414
7.6HIGH
What is CVE-2026-47414?
The PraisonAI Platform suffers from an Insecure Direct Object Reference vulnerability, primarily affecting versions prior to 0.1.4. This flaw permits unauthorized access to sensitive resources by not adequately validating label_id and issue_id against the user's workspace. Five API endpoints, including those for updating and deleting labels associated with workspaces and issues, fail to enforce proper access checks, potentially exposing users to data leaks or manipulation. Version 0.1.4 of the platform addresses this crucial issue.
Affected Version(s)
praisonai-platform < 0.1.4
