CyberRota Analysis
AI-GeneratedThe PraisonAI Platform prior to version 0.1.4 is vulnerable to an authorization bypass that allows any workspace member to tamper with workspace metadata and settings through the `PATCH /workspaces/{workspace_id}` endpoint. This vulnerability can lead to configuration injection, potentially affecting the integrity and security of the platform's operations. Organizations using affected versions should prioritize updating to version 0.1.4 to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling workspace metadata + settings tampering. The `PATCH /workspaces/{workspace_id}` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`). Any member can rewrite the workspace's `name`, `description`, and the `settings` JSON blob. The settings field is a free-form JSON object — depending on which downstream code reads it, this becomes a configuration-injection primitive for any setting the platform exposes there. PraisonAI Platform version 0.1.4 patches the issue.