← العودة للجدول
CVE-2026-47407
CVE-2026-47407 — GHSA: PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation
📅 2026-05-29
🔴 Critical 🔥 No GHSA AI Attack Supply Chain

📋 الوصف الكامل

## Summary The Platform server exposes resources under `/api/v1/workspaces/{workspace_id}/...` and protects them with a `require_workspace_member(workspace_id)` FastAPI dependency. The dependency only checks that the caller is a member of the workspace_id in the URL prefix. The route handlers then look up the inner resource (`agent_id`, `issue_id`, `project_id`, `label_id`, `comment_id`, `depende

💻 الأنظمة المتأثرة

GHSA: PraisonAI Platform

⚠️ نوع التهديد

AI Attack

🔗 CVE ID

CVE-2026-47407

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←