CVE-2026-62179
Awaiting Analysis Awaiting Analysis - Queue

Authorization Bypass in PraisonAI Issue Dependency Deletion

Vulnerability report for CVE-2026-62179, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

PraisonAI is a multi-agent teams system. In `praisonai-platform` prior to version 0.1.9, issue dependency deletion can be authorized against the wrong side of a dependency edge. A workspace member cannot delete a dependency through the owner-created issue endpoint, but can delete the same dependency through a member-owned related issue endpoint because the route accepts either endpoint and checks delete permission only against the caller-selected URL issue. Version 0.1.9 patches the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
MervinPraison praisonai-platform < 0.1.9

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in PraisonAI allows workspace members with ordinary access to delete dependency edges from owner-created issues by exploiting a flawed authorization check. The system incorrectly verifies deletion permissions based on the URL issue selected by the user rather than the primary issue linked to the dependency. This enables members to bypass owner/admin-only controls by using a related member-owned issue endpoint.

Detection Guidance

To detect this vulnerability, review PraisonAI platform logs for unauthorized dependency deletions. Check for HTTP 204 success responses from member-owned issue endpoints when attempting to delete dependencies tied to owner-created issues. Verify if workspace members can modify dependency edges without proper authorization.

Impact Analysis

If you are a workspace owner or admin, an attacker with member access could delete critical dependency relationships in your issues, disrupting workflows or removing important state like blocks or blocked_by relationships. This could lead to miscommunication, project delays, or loss of data integrity in your multi-agent system.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized users to alter or delete dependency relationships, potentially violating data integrity or audit trail requirements in GDPR or HIPAA. Unauthorized modifications to workflow state may lead to non-compliance with record-keeping or access control provisions.

Mitigation Strategies

Upgrade praisonai-platform to version 0.1.9 or later to patch the issue. Review and restrict workspace member permissions to prevent unauthorized dependency modifications. Implement stricter authorization checks requiring admin/owner authority for dependency deletions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62179. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart