Authorization Flaw in PraisonAI's Multi-Agent Teams System
CVE-2026-62179

6.5MEDIUM

Key Information:

Vendor
CVE Published:
7 October 2026

What is CVE-2026-62179?

PraisonAI is a multi-agent teams system that allows users to collaborate on projects. In versions prior to 0.1.9, an authorization flaw exists where a workspace member can delete a dependency through a member-owned related issue endpoint, despite not having permission through the owner-created issue endpoint. This flaw arises because the routing only checks delete permissions against the selected URL issue, leading to potential inadvertent dependency deletions. The issue has been addressed in version 0.1.9.

Affected Version(s)

praisonai-platform < 0.1.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.