Executive brief
PraisonAI Platform, a tool for managing AI workflows and issue dependencies, contains a security flaw that allows regular workspace members to bypass administrative restrictions. Specifically, a member can delete task dependencies created by an owner or administrator by exploiting how the system validates permissions. This could lead to unauthorized changes in project workflows, potentially disrupting operations or removing critical project constraints without proper oversight.
Technical details
A missing authorization vulnerability (CWE-862) exists in the DELETE dependency route of PraisonAI Platform. The route `DELETE /workspaces/{workspace_id}/issues/{issue_id}/dependencies/{dep_id}` accepts either endpoint of a dependency edge but only validates the caller's delete permission against the `issue_id` provided in the URL. A workspace member can bypass a 403 Forbidden response on an owner-owned issue by instead targeting a related member-owned issue endpoint that shares the same dependency edge. Because the system validates the request against the member-owned issue's creator, the member can successfully delete the dependency edge belonging to the owner's issue. This issue is fixed in version 0.1.9.
Affected products
- MervinPraison PraisonAI Platform (praisonai-platform) < 0.1.9
Timeline
- 2026-06-17: patched: Fix commit 846568c7a5d8ce9e71e56e4c213f027c04909753
- 2026-06-25: advisory: GHSA-mxmx-rh57-jx58 published
- 2026-07-10: disclosed: CVE-2026-61441 published to NVD