CVE Explorer
CVE-2026-47399
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization flaw that allows an authenticated user from one workspace to access, modify, and delete objects belonging to another workspace by supplying the victim object's global UUID. The affected pattern appears in workspace-scoped routes such as agents, projects, issues, and comments. The route layer verifies that the c
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9f0ad7db2b80101bc56c7357ac0aa79981545ad148015863964be5ef8e67cbe4 · sha256:2b4ba4fa34c24bc5… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9f0ad7db2b80101bc56c7357ac0aa79981545ad148015863964be5ef8e67cbe4 · sha256:2b4ba4fa34c24bc5… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"praisonai-platform","vendor":"MervinPraison","versions":[{"status":"affected","version":"< 0.1.4"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9f0ad7db2b80101bc56c7357ac0aa79981545ad148015863964be5ef8e67cbe4 · sha256:2b4ba4fa34c24bc5… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9f0ad7db2b80101bc56c7357ac0aa79981545ad148015863964be5ef8e67cbe4 · sha256:2b4ba4fa34c24bc5… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9f0ad7db2b80101bc56c7357ac0aa79981545ad148015863964be5ef8e67cbe4 · sha256:2b4ba4fa34c24bc5… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9f0ad7db2b80101bc56c7357ac0aa79981545ad148015863964be5ef8e67cbe4 · sha256:2b4ba4fa34c24bc5… · /containers/cna/problemTypes/1/descriptions/0
Source references
4 source assertions{"name":"https://github.com/MervinPraison/PraisonAI/commit/24385d64876577620f749957bd4814f162f4ca47","tags":["x_refsource_MISC"],"url":"https://github.com/MervinPraison/PraisonAI/commit/24385d64876577620f749957bd4814f162f4ca47"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9f0ad7db2b80101bc56c7357ac0aa79981545ad148015863964be5ef8e67cbe4 · sha256:2b4ba4fa34c24bc5… · /containers/cna/references/2
{"name":"https://github.com/MervinPraison/PraisonAI/pull/1686","tags":["x_refsource_MISC"],"url":"https://github.com/MervinPraison/PraisonAI/pull/1686"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9f0ad7db2b80101bc56c7357ac0aa79981545ad148015863964be5ef8e67cbe4 · sha256:2b4ba4fa34c24bc5… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6h6v-6m7w-7vxx"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9f0ad7db2b80101bc56c7357ac0aa79981545ad148015863964be5ef8e67cbe4 · sha256:2b4ba4fa34c24bc5… · /containers/adp/0/references/0
{"name":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6h6v-6m7w-7vxx","tags":["x_refsource_CONFIRM"],"url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-6h6v-6m7w-7vxx"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9f0ad7db2b80101bc56c7357ac0aa79981545ad148015863964be5ef8e67cbe4 · sha256:2b4ba4fa34c24bc5… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.