Praisonai-platform
23 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Praisonai-platform, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Praisonai-platform CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 4 |
| 2026-07 | 16 |
| 2026-08 | 1 |
| 2026-09 | 2 |
Severity
How the 23 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical5
- High11
- Medium2
Latest CVEs
The 15 most recently published vulnerabilities affecting Praisonai-platform.
- CVE-2026-57147praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery9.8
- CVE-2026-57148praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)9.8
- CVE-2026-48169PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API8.8
- CVE-2026-47419praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR8.3
- CVE-2026-47418praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR8.1
- CVE-2026-47417praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR8.1
- CVE-2026-47416praisonai-platform: Any workspace member can promote themselves (or any other member) to owner via PATCH /workspaces/{id}/members/{user_id}9.6
- CVE-2026-47415praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR8.3
- CVE-2026-47414praisonai-platform: Label endpoints accept any label_id and any issue_id without workspace ownership check, cross-workspace label edit/delete and issue-label-link IDOR7.6
- CVE-2026-47413praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members9.6
- CVE-2026-47412praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}8.1
- CVE-2026-47411praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}6.5
- CVE-2026-47410praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset9.8
- CVE-2026-47409praisonai-platform: Any workspace member can remove any other member (including the owner) via DELETE /workspaces/{id}/members/{user_id}8.1
- CVE-2026-47408praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership6.5
Product grouping is registry-driven, with AI assist and human review. How it works