What is CVE-2026-48169?
PraisonAI Platform API versions prior to 0.1.4 contain authorization failures that break workspace isolation. The service layer performs global primary-key lookups for issues and projects without verifying workspace ownership, allowing attackers to bypass access controls. Users should immediately upgrade to version 0.1.4 or later to patch these vulnerabilities.
Azərbaycanca: PraisonAI multi-agent platform API-nin 0.1.4-dən əvvəlki versiyalarında authorization zəiflikləri workspace izolyasiyasını pozur. Hər hansı autentifikasiya olunmuş istifadəçi qlobal primary-key lookup vasitəsilə digər workspace-lərə aid issues və projects məlumatlarına icazəsiz giriş əldə edə bilər. Platformanı dərhal 0.1.4 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which component of the PraisonAI platform contains the authorization failure that breaks workspace isolation?
The vulnerability exists in the service layer, where global primary-key lookups for issues and projects are performed without verifying workspace ownership.
To which version should the PraisonAI platform be upgraded to fix CVE-2026-48169?
Users should immediately upgrade to version 0.1.4 or later to patch the vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.