Junglewise Threat Intelligence

CVE-2026-47412: MervinPraison PraisonAI Platform authorization bypass in workspace deletion

CVE-2026-47412 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: praisonai-platform (PyPI). Vendors: MervinPraison, PyPI.

Executive brief

PraisonAI Platform, a system for managing multi-agent AI teams, contains a flaw that allows any member of a workspace to permanently delete it. An attacker with basic member-level access can trigger a total deletion of all projects, agents, comments, and member records within that workspace. This action is irreversible, as the system lacks a recovery window or confirmation process, leading to a complete loss of data and service for the affected organization.

Technical details

An authorization bypass exists in the `DELETE /workspaces/{workspace_id}` endpoint of the PraisonAI Platform. The endpoint is protected by the `require_workspace_member` dependency, which defaults to a `min_role` of "member" rather than "owner." Consequently, any authenticated user with basic member privileges can issue a DELETE request that triggers a cascading database deletion of the workspace and all child entities (projects, agents, issues, etc.) via foreign-key relationships. The vulnerability is exacerbated by the lack of a soft-delete mechanism or confirmation tokens. The issue is addressed in version 0.1.4 by enforcing a "owner" role requirement for this destructive operation.

Affected products

  • MervinPraison praisonai-platform <= 0.1.2

Timeline

  • 2026-05-19: patched: Fix merged in PR #1686
  • 2026-05-19: advisory: GitHub Advisory GHSA-g8rr-7rj2-f627 published
  • 2026-07-21: disclosed: CVE-2026-47412 published to NVD

References

Related threats