
🔴 PraisonAI Platform, Inadequate Authorization, #CVE-2026-62179 (High) -DC-Oct2026-2977 https://dailycve.com/praisonai-platform-inadequate-authorization-cve-2026-62179-high-dc-oct2026-2977/
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
PraisonAI is a multi-agent teams system. In `praisonai-platform` prior to version 0.1.9, issue dependency deletion can be authorized against the wrong side of a dependency edge. A workspace member cannot delete a dependency through the owner-created issue endpoint, but can delete the same dependency through a member-owned related issue endpoint because the route accepts either endpoint and checks delete permission only against the caller-selected URL issue. Version 0.1.9 patches the issue.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

🔴 PraisonAI Platform, Inadequate Authorization, #CVE-2026-62179 (High) -DC-Oct2026-2977 https://dailycve.com/praisonai-platform-inadequate-authorization-cve-2026-62179-high-dc-oct2026-2977/