Junglewise Threat Intelligence

CVE-2026-48169: PraisonAI Platform IDOR and privilege escalation in Platform API

CVE-2026-48169 · Severity: high · CVSS 8.8 · Published 2026-05-29

Technologies: praisonai-platform (PyPI). Vendors: MervinPraison, PyPI.

Executive brief

PraisonAI Platform, a tool for managing AI projects and workspaces, contains security flaws that allow any registered user to access or modify data belonging to other organizations. Additionally, a low-privileged member of a workspace can exploit these flaws to promote themselves to an administrator and lock out the original owners. This could lead to a total loss of data privacy and unauthorized control over corporate AI projects.

Technical details

The PraisonAI Platform API suffers from two primary authorization failures. First, the service layer for 'issues' and 'projects' (e.g., issue_service.py) performs global database lookups using primary keys without verifying workspace ownership, enabling cross-workspace IDOR. An attacker can read, update, or delete resources in any workspace by manipulating UUIDs in API requests. Second, member management endpoints in workspaces.py only require a 'member' role for access and lack server-side checks for role hierarchy or self-promotion. This allows any workspace member to escalate their privileges to 'owner' and remove other members, including the original creator. These issues are addressed in version 0.1.4.

Affected products

  • MervinPraison praisonai-platform <= 0.1.2

Timeline

  • 2026-05-19: advisory: Initial disclosure on GitHub
  • 2026-05-29: patched: Updated advisory and patch availability confirmed

References

Related threats