SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-47413

CRITICAL · CVSS 9.6 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

The PraisonAI Platform versions prior to 0.1.4 are vulnerable to a critical privilege escalation and cross-tenant member injection flaw, allowing low-privilege users to elevate their access by adding any user as an owner of the workspace. This vulnerability can lead to unauthorized control over workspaces, potentially compromising sensitive data and operations. Organizations using affected versions should prioritize upgrading to version 0.1.4 to mitigate this severe security risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-47413
Severity
CRITICAL
CVSS
9.6
EPSS
0.21%

Original NVD Description

PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST /workspaces/{workspace_id}/members` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`) and forwards the request body's `user_id` and `role` straight into `MemberService.add(workspace_id, user_id, role)`, which has no caller-permission check. A user with the lowest workspace privilege can add any user (including a new attacker-controlled second account, or an existing account they want to grief) as owner of the workspace. PraisonAI Platform version 0.1.4 patches the issue.