Authorization Flaw in PraisonAI's Multi-Agent Teams System
CVE-2026-62179
6.5MEDIUM
What is CVE-2026-62179?
PraisonAI is a multi-agent teams system that allows users to collaborate on projects. In versions prior to 0.1.9, an authorization flaw exists where a workspace member can delete a dependency through a member-owned related issue endpoint, despite not having permission through the owner-created issue endpoint. This flaw arises because the routing only checks delete permissions against the selected URL issue, leading to potential inadvertent dependency deletions. The issue has been addressed in version 0.1.9.
Affected Version(s)
praisonai-platform < 0.1.9
