info: name: praisonai cve: CVE-2026-47414 summary: PraisonAI Platform Insecure Direct Object Reference (IDOR) on label endpoints details: PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system (pip package 'praisonai-platform'). In versions prior to 0.1.4, five label endpoints — PATCH /workspaces/{workspace_id}/labels/{label_id}, DELETE /workspaces/{workspace_id}/labels/{label_id}, POST /issues/{issue_id}/labels/{label_id}, DELETE /issues/{issue_id}/labels/{label_id}, GET /issues/{issue_id}/labels — gate access only on require_workspace_member(workspace_id) and pass URL-supplied label_id and issue_id directly into the service layer without verifying that the referenced label or issue belongs to the same workspace. A workspace member can therefore read, modify, or delete labels and issue-label associations belonging to any other workspace, resulting in an Insecure Direct Object Reference (IDOR) vulnerability. The fix in praisonai-platform version 0.1.4 adds workspace ownership validation for label and issue resources before any mutation or read operation. cvss: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L severity: HIGH security_advise: Upgrade praisonai-platform to version 0.1.4 or later via 'pip install --upgrade praisonai-platform>=0.1.4'. rule: version < "0.1.4" references: - https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-5jx9-w35f-vp65 - https://github.com/MervinPraison/PraisonAI/pull/1685 - https://github.com/MervinPraison/PraisonAI/commit/ef79b7a0561796ad9807f0f09538c25cc78d3619 - https://nvd.nist.gov/vuln/detail/CVE-2026-47414 - https://osv.dev/vulnerability/CVE-2026-47414 - https://pypi.org/project/praisonai-platform