CVE-2026-61440
MEDIUMPraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints
Title source: cnaDescription
PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. Attackers with workspace member privileges can exploit PATCH and POST/DELETE endpoints to alter shared label taxonomy and manipulate issue-label associations without owner or admin authorization.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-xxgv-vgvj-qvxh)
https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-xxgv-vgvj-qvxh
Patch patch
https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753
Third Party Advisory third-party-advisory
VulnCheck Advisory: PraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints
https://www.vulncheck.com/advisories/praisonai-platform-before-authorization-bypass-via-label-endpoints
Scores
CVSS v3
6.5
EPSS
0.0021
EPSS Percentile
11.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (2)
MervinPraison/PraisonAI
< 0.1.9
MervinPraison/PraisonAI
0.1.9
Published
Jul 15, 2026
Tracked Since
Jul 15, 2026