Executive brief
PraisonAI Platform, a framework for managing AI agents and projects, contains a security flaw where standard workspace members can modify or delete resources created by administrators or owners. By exploiting this, a regular user can change project details, reassign ownership to themselves, and subsequently delete entire projects or modify AI agent instructions. This could lead to unauthorized data modification, service disruption, and loss of critical project configurations.
Technical details
A missing authorization check (CWE-862) exists in the PATCH routes for projects, issues, and agents in PraisonAI Platform before version 0.1.9. While DELETE routes correctly enforce 'require_delete_permission' (restricting actions to owners or admins), the corresponding PATCH routes only require the 'workspace-member' role. An authenticated workspace member can use a PATCH request to modify resource fields, including the 'lead_id' or 'owner_id'. By reassigning these ownership fields to their own user ID, the member can then successfully call the DELETE route, effectively bypassing the intended authorization model to delete or alter resources they do not own.
Affected products
- MervinPraison PraisonAI Platform < 0.1.9
Timeline
- 2026-06-17: patched: Fix committed to repository
- 2026-06-25: advisory: GitHub Security Advisory published
- 2026-07-11: disclosed: NVD publication date