CVE Tools

Praisonai-platform

23 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Praisonai-platform, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Praisonai-platform CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Praisonai-platform CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-064
2026-0716
2026-081
2026-092

Severity

How the 23 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical528%
  • High1161%
  • Medium211%

Latest CVEs

The 15 most recently published vulnerabilities affecting Praisonai-platform.

  1. CVE-2026-57147praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery9.8
  2. CVE-2026-57148praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)9.8
  3. CVE-2026-48169PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API8.8
  4. CVE-2026-47419praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR8.3
  5. CVE-2026-47418praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR8.1
  6. CVE-2026-47417praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR8.1
  7. CVE-2026-47416praisonai-platform: Any workspace member can promote themselves (or any other member) to owner via PATCH /workspaces/{id}/members/{user_id}9.6
  8. CVE-2026-47415praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR8.3
  9. CVE-2026-47414praisonai-platform: Label endpoints accept any label_id and any issue_id without workspace ownership check, cross-workspace label edit/delete and issue-label-link IDOR7.6
  10. CVE-2026-47413praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members9.6
  11. CVE-2026-47412praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}8.1
  12. CVE-2026-47411praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}6.5
  13. CVE-2026-47410praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset9.8
  14. CVE-2026-47409praisonai-platform: Any workspace member can remove any other member (including the owner) via DELETE /workspaces/{id}/members/{user_id}8.1
  15. CVE-2026-47408praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store