PraisonAI is a multi-agent teams system. In `praisonai-platform` prior to version 0.1.9, issue dependency deletion can be authorized against the wrong side of a dependency edge. A workspace member cannot delete a dependency through the owner-created issue endpoint, but can delete the same dependency through a member-owned related issue endpoint because the route accepts either endpoint and checks delete permission only against the caller-selected URL issue. Version 0.1.9 patches the issue.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-mxmx-rh57-jx58 PraisonAI: Platform members can delete owner issue dependencies through member-owned related issues
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 07 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description PraisonAI is a multi-agent teams system. In `praisonai-platform` prior to version 0.1.9, issue dependency deletion can be authorized against the wrong side of a dependency edge. A workspace member cannot delete a dependency through the owner-created issue endpoint, but can delete the same dependency through a member-owned related issue endpoint because the route accepts either endpoint and checks delete permission only against the caller-selected URL issue. Version 0.1.9 patches the issue.
Title PraisonAI: Platform members can delete owner issue dependencies through member-owned related issues
Weaknesses CWE-862
CWE-863
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-07T14:29:02.988Z

Reserved: 2026-07-13T14:16:29.575Z

Link: CVE-2026-62179

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T15:17:23.073

Modified: 2026-10-07T15:17:23.073

Link: CVE-2026-62179

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses