PT-2026-107539 · Unknown · Praisonai-Platform
CVE-2026-62179
·
Published
2026-10-07
·
Updated
2026-10-07
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
praisonai-platform versions prior to 0.1.9
Description
Issue dependency deletion can be authorized against the wrong side of a dependency edge. A workspace member can delete a dependency from an owner-created issue by accessing it through a member-owned related issue endpoint. This occurs because the route accepts either endpoint and only verifies delete permissions against the caller-selected URL issue, bypassing the intended restriction on owner-created workflow state. Additionally, workspace members can create dependency edges on owner-created issues without owner or admin authority.
API Endpoints:
DELETE /workspaces/{workspace id}/issues/{issue id}/dependencies/{dep id}POST /workspaces/{workspace id}/issues/{issue id}/dependencies/
Vulnerable Parameters or Variables:
workspace idissue iddep id
Function Names:
require delete permission()
Recommendations
Update praisonai-platform to version 0.1.9.
As a temporary workaround, restrict the use of the
DELETE /workspaces/{workspace id}/issues/{issue id}/dependencies/{dep id} endpoint to only users with admin or owner privileges.Exploit
Fix
Missing Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Praisonai-Platform