| CVE-2026-47412 |
unknown |
— |
— |
|
|
|
3d ago |
praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id} |
| CVE-2026-47415 |
unknown |
— |
— |
|
|
|
3d ago |
praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR |
| CVE-2026-47413 |
unknown |
— |
— |
|
|
|
3d ago |
praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members |
| CVE-2026-47411 |
unknown |
— |
— |
|
|
|
3d ago |
praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id} |
| CVE-2026-47417 |
unknown |
— |
— |
|
|
|
3d ago |
praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR |
| CVE-2026-47418 |
unknown |
— |
— |
|
|
|
3d ago |
praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR |
| CVE-2026-47416 |
unknown |
— |
— |
|
|
|
5d ago |
praisonai-platform: Any workspace member can promote themselves or others to owner via PATCH /workspaces/{id}/members/{user_id} |
| CVE-2026-47409 |
unknown |
— |
— |
|
|
|
5d ago |
praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role |
| CVE-2026-47414 |
unknown |
— |
— |
|
|
|
5d ago |
praisonai-platform: Label endpoints' unchecked label_id/issue_id enable cross-workspace label IDOR (edit, delete, link) |
| CVE-2026-47406 |
unknown |
— |
— |
|
|
|
5d ago |
praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks |
| CVE-2026-47410 |
unknown |
— |
— |
|
|
|
5d ago |
praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset |
| CVE-2026-47405 |
unknown |
— |
— |
|
|
|
5d ago |
PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership |
| CVE-2026-47399 |
unknown |
— |
— |
|
|
|
5d ago |
PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID |
| CVE-2026-47407 |
unknown |
— |
— |
|
|
|
5d ago |
PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation |
| CVE-2026-47408 |
unknown |
— |
— |
|
|
|
5d ago |
praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership |
| CVE-2026-48169 |
unknown |
— |
— |
|
|
|
5d ago |
PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API |