Executive brief
PraisonAI Platform, a system for managing multi-agent AI teams, contains a flaw that allows any member of a workspace to permanently delete it. An attacker with basic member-level access can trigger a total deletion of all projects, agents, comments, and member records within that workspace. This action is irreversible, as the system lacks a recovery window or confirmation process, leading to a complete loss of data and service for the affected organization.
Technical details
An authorization bypass exists in the `DELETE /workspaces/{workspace_id}` endpoint of the PraisonAI Platform. The endpoint is protected by the `require_workspace_member` dependency, which defaults to a `min_role` of "member" rather than "owner." Consequently, any authenticated user with basic member privileges can issue a DELETE request that triggers a cascading database deletion of the workspace and all child entities (projects, agents, issues, etc.) via foreign-key relationships. The vulnerability is exacerbated by the lack of a soft-delete mechanism or confirmation tokens. The issue is addressed in version 0.1.4 by enforcing a "owner" role requirement for this destructive operation.
Affected products
- MervinPraison praisonai-platform <= 0.1.2
Timeline
- 2026-05-19: patched: Fix merged in PR #1686
- 2026-05-19: advisory: GitHub Advisory GHSA-g8rr-7rj2-f627 published
- 2026-07-21: disclosed: CVE-2026-47412 published to NVD