« Volver al listado

Praisonai

Praisonai Platform: vulnerabilidades y CVE

Praisonai Platform tiene 16 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE16
Últimos 12 meses16
Críticas5
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-57148Crítica (9.8)0.64%—15 sept 2026
PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup…
CVE-2026-57147Crítica (9.8)0.77%—15 sept 2026
PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production…
CVE-2026-47416Crítica (9.6)0.36%—21 jul 2026
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}`…
CVE-2026-47415Alta (8.3)0.39%—21 jul 2026
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The issue CRUD endpoints (`GET / PATCH / DELETE…
CVE-2026-47414Alta (7.6)0.38%—21 jul 2026
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. Five label endpoints — `PATCH…
CVE-2026-47413Crítica (9.6)0.36%—21 jul 2026
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST /workspaces/{workspace_id}/members`…
CVE-2026-47412Alta (8.1)0.53%—21 jul 2026
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE /workspaces/{workspace_id}` endpoint is…
CVE-2026-47411Media (6.5)0.34%—21 jul 2026
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling workspace metadata + settings tampering. The `PATCH…
CVE-2026-47410Crítica (9.8)0.64%—21 jul 2026
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcoded literal…
CVE-2026-47408Media (6.5)0.40%—21 jul 2026
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The `GET /workspaces/{workspace_id}/issues/{issue_id}/activity`…
CVE-2026-47406Alta (8.1)0.41%—21 jul 2026
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The dependency endpoints (`POST/GET…
CVE-2026-47405Alta (8.8)0.51%—21 jul 2026
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization check that allows any authenticated low-privilege workspace member to…
CVE-2026-47399Alta (8.8)0.51%—21 jul 2026
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization flaw that allows an…
CVE-2026-61440Alta (7.1)0.38%—15 jul 2026
PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. Attackers…
CVE-2026-61442Alta (7.1)0.46%—11 jul 2026
PraisonAI Platform (praisonai-platform) before 0.1.9 fails to enforce owner/admin authorization on the PATCH routes for projects, issues, and agents, which only require workspace-member role. A workspace member can…
CVE-2026-61441Alta (7.1)0.41%—10 jul 2026
PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either endpoint of a dependency edge and checks delete permission only…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services11
  2. T1190 Exploit Public-Facing Application3
  3. T1565.002 Transmitted Data Manipulation3
  4. T1005 Data from Local System2
  5. T1068 Exploitation for Privilege Escalation2
  6. T1078 Valid Accounts2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Praisonai