PT-2026-107539 · Unknown · Praisonai-Platform

CVE-2026-62179

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions praisonai-platform versions prior to 0.1.9
Description Issue dependency deletion can be authorized against the wrong side of a dependency edge. A workspace member can delete a dependency from an owner-created issue by accessing it through a member-owned related issue endpoint. This occurs because the route accepts either endpoint and only verifies delete permissions against the caller-selected URL issue, bypassing the intended restriction on owner-created workflow state. Additionally, workspace members can create dependency edges on owner-created issues without owner or admin authority.
API Endpoints:
  • DELETE /workspaces/{workspace id}/issues/{issue id}/dependencies/{dep id}
  • POST /workspaces/{workspace id}/issues/{issue id}/dependencies/
Vulnerable Parameters or Variables:
  • workspace id
  • issue id
  • dep id
Function Names:
  • require delete permission()
Recommendations Update praisonai-platform to version 0.1.9. As a temporary workaround, restrict the use of the DELETE /workspaces/{workspace id}/issues/{issue id}/dependencies/{dep id} endpoint to only users with admin or owner privileges.

Exploit

Fix

Missing Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62179
GHSA-MXMX-RH57-JX58

Affected Products

Praisonai-Platform