Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4183 articles · 197350 vulns · 37/41 feeds (7d)
← Back to list
6.5
CVE-2026-61441PATCHED
mervinpraison · praisonai

PraisonAI Platform before 0.1.9 Authorization Bypass via Dependencies

Description

PraisonAI Platform (praisonai-platform) before 0.1.9 improperly authorizes deletion of issue dependencies. The DELETE dependency route accepts either endpoint of a dependency edge and checks delete permission only against the caller-selected URL issue. A workspace member who cannot delete a dependency through an owner-created issue endpoint (which returns 403) can delete the same dependency edge by targeting a related member-owned issue endpoint, because permission is validated against the member-owned issue's owner. This allows members to bypass owner/admin authorization and remove owner-created issue dependencies.

Affected Products

VendorProductVersions
mervinpraisonpraisonai0, 0.1.8

References

  • https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-mxmx-rh57-jx58(vendor-advisory)
  • https://github.com/MervinPraison/PraisonAI/commit/846568c7a5d8ce9e71e56e4c213f027c04909753(patch)
  • https://www.vulncheck.com/advisories/praisonai-platform-before-authorization-bypass-via-dependencies(third-party-advisory)

Related News (1 articles)

Tier C
VulDB46d ago
CVE-2026-61441 | MervinPraison PraisonAI up to 0.1.8 Dependency Management improper authorization
→ No new info (linked only)
CVSS 3.16.5 CRITICAL
CISA KEV❌ No
Actively exploited❌ No
Patch available
0.1.9
CWECWE-862
PublishedJul 10, 2026
Last enriched46d agov2
Trending Score0
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-55533
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
Trending: 44
HIGHCVE-2026-55538
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
Trending: 44
HIGHCVE-2026-55525
PraisonAI: SSRF via redirect-following in praisonaiagents web_crawl
Trending: 44
HIGHCVE-2026-55532
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
Trending: 35
HIGHCVE-2026-55537
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
Trending: 35

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 10, 2026
Discovered by ZDM
Jul 10, 2026
Patch Available
Jul 10, 2026
Updated: severity, affectedVersions
Jul 10, 2026

Version History

v2
Last enriched 46d ago
v2Tier C46d ago

Updated severity to CRITICAL, affected versions to include 0.1.8, and noted that no exploit is available.

severityaffectedVersions
via VulDB
v146d ago

Initial creation