PT-2026-55200 · Praisonai · Praisonai

·

CVE-2026-58653

·

Published

2026-06-18

·

Updated

2026-07-02

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PraisonAI versions prior to 0.1.7
Description An authorization bypass occurs because the software fails to validate that the project id provided in the request bodies for creating and updating issues belongs to the workspace specified in the URL. This allows an attacker to create issues that reference projects from different workspaces, leading to cross-tenant data pollution within project statistics aggregation.
Recommendations Update PraisonAI to version 0.1.7 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58653
GHSA-2FJJ-QQG8-FG7X

Affected Products

Praisonai