Executive brief
PraisonAI Platform, a collaborative AI workspace, contains a security flaw that allows regular workspace members to perform administrative actions on shared labels. An authorized user within a workspace can rename or change the colors of shared labels and modify labels on issues created by the workspace owner. This could lead to unauthorized changes in project organization, data categorization, and workflow management, potentially disrupting operations or misrepresenting the status of tasks.
Technical details
A missing authorization vulnerability (CWE-862) exists in the PraisonAI Platform's label management endpoints. While direct label deletion is restricted to admins, the PATCH, POST, and DELETE endpoints for label modification and issue-label associations only require basic workspace membership. Specifically, the routes in `src/praisonai-platform/praisonai_platform/api/routes/labels.py` fail to call `require_delete_permission` or equivalent ownership checks before executing `LabelService` updates. An authenticated attacker with 'member' privileges can exploit this to alter the shared triage taxonomy and manipulate issue states without owner or admin authorization. The issue is resolved in version 0.1.9.
Affected products
- MervinPraison PraisonAI Platform < 0.1.9
Timeline
- 2026-06-17: patched: Fix committed to repository
- 2026-06-25: advisory: GitHub Security Advisory published
- 2026-07-15: disclosed: NVD publication date