Multiple vulnerabilities in PraisonAI Platform were disclosed and assigned CVE-2026-47399, CVE-2026-47405, CVE-2026-47406, CVE-2026-47407, and CVE-2026-47409, affecting versions prior to 0.1.4. The flaws allowed authenticated users to access, modify, or delete objects across other workspaces by abusing global object IDs and weak workspace-scoped route validation, while separate authorization failures let ordinary workspace members promote themselves to owner, alter member roles, remove other users, and even delete or fully take over a workspace. One issue also allowed cross-workspace issue linking through unchecked dependency endpoints, and the combined impact broke tenant isolation across agents, projects, issues, comments, and membership management.
The vendor merged fixes into the PraisonAI repository through pull request #1686 and commit 24385d64876577620f749957bd4814f162f4ca47, adding workspace ownership checks to service and route layers, tightening role-based access control so only owners can grant privileged roles, and scoping dependency operations to authorized parent issues. The update also changed the default platform bind address from 0.0.0.0 to 127.0.0.1, reducing exposure for internet-reachable deployments. Earlier reporting had grouped the PraisonAI bugs among accepted GitHub Security Lab findings that initially lacked public CVEs, but the issues are now publicly tracked and fixed in version 0.1.4.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Public CVE records were published for several PraisonAI Platform vulnerabilities affecting versions prior to 0.1.4, covering cross-workspace object access, dependency endpoint IDOR, member-to-owner privilege escalation, combined IDOR and role escalation, and arbitrary member removal. The advisories state that version 0.1.4 fixes these tenancy and authorization issues.
Bugflation published a roundup of nine accepted GitHub Security Lab reports without public CVEs, including PraisonAI issues involving privilege escalation and access-control bypass. The post states the affected projects had accepted or remediated the reports and grouped them as a no-CVE Taskflow Agent cluster for tracking.
PraisonAI merged pull request #1686 into main, adding workspace ownership checks across platform services, tightening role-based access control, scoping dependency deletion, and changing the default bind address from 0.0.0.0 to 127.0.0.1. The associated commit notes the code was fixed on main while advisory publication and PyPI release were still pending.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcebugflation.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.