PT-2026-55200 · Praisonai · Praisonai
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PraisonAI versions prior to 0.1.7
Description
An authorization bypass occurs because the software fails to validate that the
project id provided in the request bodies for creating and updating issues belongs to the workspace specified in the URL. This allows an attacker to create issues that reference projects from different workspaces, leading to cross-tenant data pollution within project statistics aggregation.Recommendations
Update PraisonAI to version 0.1.7 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Praisonai