CVE-2026-47408: praisonai-platform: IDOR exposes cross-tenant activity logs
GHSA-27p4-pjqv-whgj MEDIUM CISA: TRACK*A missing workspace ownership check in PraisonAI Platform's issue-activity API lets any authenticated workspace member silently read the full activity log of issues belonging to any other tenant by substituting a foreign issue UUID in the request path. Activity logs capture actor identities, action types, and before/after field values for every tracked change—giving an attacker a high-fidelity view of another organization's AI agent workflows, team members, and any sensitive operational data embedded in issue histories. The package carries 59 additional CVEs, signaling a systemic pattern of insufficient authorization controls that multiplies the blast radius for multi-tenant deployments. Upgrade to praisonai-platform 0.1.4 immediately; until patched, restrict API access to trusted network segments and audit logs for requests where the workspace_id in the URL path does not match the workspace that owns the queried issue_id.
What is the risk?
Medium severity (CVSS 6.5) in isolation, but elevated in multi-tenant AI agent deployments where tenant isolation is a hard security boundary. Exploitation is trivial—a single authenticated GET request with a known issue UUID is sufficient, requiring no elevated privileges, no user interaction, and no specialized tooling. The asymmetry in the codebase (the workspace-level endpoint is correctly scoped; only the issue-level variant is not) suggests the gap was introduced incrementally and may not be the only such omission. The 59 other CVEs in the same package reinforce that authorization controls are applied inconsistently across the codebase.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| PraisonAI | pip | <= 0.1.2 | 0.1.4 |
Do you use PraisonAI? You're affected.
How severe is it?
What is the attack surface?
What should I do?
5 steps-
Upgrade to praisonai-platform 0.1.4, which adds a workspace-scoped IssueService.get() guard before serving activity data.
-
If immediate patching is blocked, apply network-level controls to restrict the /workspaces/*/issues/*/activity endpoint to authenticated internal clients only.
-
Audit API access logs for requests where workspace_id in the URL path differs from the workspace that owns the queried issue_id—these are exploitation indicators.
-
Conduct a full authorization audit of all API endpoints in the platform given the pattern of 59 CVEs; apply the same workspace-scoped guard pattern used in list_workspace_activity to every issue-scoped route.
-
Treat all issue UUIDs as potentially enumerated and review whether sensitive AI agent configuration, credentials, or workflow data entered issue fields or comments.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-47408?
A missing workspace ownership check in PraisonAI Platform's issue-activity API lets any authenticated workspace member silently read the full activity log of issues belonging to any other tenant by substituting a foreign issue UUID in the request path. Activity logs capture actor identities, action types, and before/after field values for every tracked change—giving an attacker a high-fidelity view of another organization's AI agent workflows, team members, and any sensitive operational data embedded in issue histories. The package carries 59 additional CVEs, signaling a systemic pattern of insufficient authorization controls that multiplies the blast radius for multi-tenant deployments. Upgrade to praisonai-platform 0.1.4 immediately; until patched, restrict API access to trusted network segments and audit logs for requests where the workspace_id in the URL path does not match the workspace that owns the queried issue_id.
Is CVE-2026-47408 actively exploited?
No confirmed active exploitation of CVE-2026-47408 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-47408?
1. Upgrade to praisonai-platform 0.1.4, which adds a workspace-scoped IssueService.get() guard before serving activity data. 2. If immediate patching is blocked, apply network-level controls to restrict the /workspaces/*/issues/*/activity endpoint to authenticated internal clients only. 3. Audit API access logs for requests where workspace_id in the URL path differs from the workspace that owns the queried issue_id—these are exploitation indicators. 4. Conduct a full authorization audit of all API endpoints in the platform given the pattern of 59 CVEs; apply the same workspace-scoped guard pattern used in list_workspace_activity to every issue-scoped route. 5. Treat all issue UUIDs as potentially enumerated and review whether sensitive AI agent configuration, credentials, or workflow data entered issue fields or comments.
What systems are affected by CVE-2026-47408?
This vulnerability affects the following AI/ML architecture patterns: agent frameworks, multi-tenant AI platforms, AI project management systems.
What is the CVSS score for CVE-2026-47408?
CVE-2026-47408 has a CVSS v3.1 base score of 6.5 (MEDIUM). The EPSS exploitation probability is 0.23%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0036 Data from Information Repositories AML.T0049 Exploit Public-Facing Application AML.T0087 Gather Victim Identity Information Compliance Controls Affected
What are the technical details?
Original Advisory
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The `GET /workspaces/{workspace_id}/issues/{issue_id}/activity` endpoint is gated by `require_workspace_member(workspace_id)` and dispatches to `ActivityService.list_for_issue(issue_id)`, which executes `SELECT * FROM activity WHERE issue_id = :issue_id` with no workspace constraint. A user who is a member of any workspace can read the full activity log of any issue across the entire multi-tenant deployment. PraisonAI Platform version 0.1.4 patches the issue.
Exploitation Scenario
An attacker registers a legitimate account on a multi-tenant PraisonAI Platform instance and joins any workspace. Using the companion issue-IDOR (or by harvesting UUIDs from another side channel), they obtain a target issue UUID belonging to a victim organization running AI agent workflows. They issue GET /workspaces/{their_workspace_id}/issues/{target_issue_id}/activity?limit=200 with their Bearer token. The workspace membership check passes for their own workspace, but the database executes SELECT * FROM activity WHERE issue_id = '{target_issue_id}' with no workspace constraint, returning up to 200 activity entries from the victim's workspace. The attacker extracts actor identities, triage sequences, and the details blob containing before/after field values—sufficient to map the victim's AI agent orchestration patterns, identify key personnel, and stage follow-on targeted attacks.
Weaknesses (CWE)
CWE-639 Authorization Bypass Through User-Controlled Key
Primary
CWE-639 Authorization Bypass Through User-Controlled Key
Primary
CWE-639 Authorization Bypass Through User-Controlled Key CWE-639 — Authorization Bypass Through User-Controlled Key: The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
- [Architecture and Design] For each and every data access, ensure that the user has sufficient privilege to access the record that is being requested.
- [Architecture and Design, Implementation] Make sure that the key that is used in the lookup of a specific user's record is not controllable externally by the user or that any tampering can be detected.
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N References
Timeline
Related Vulnerabilities
CVE-2026-61447 10.0 PraisonAI: RCE via unsandboxed LLM code execution
Same package: praisonai CVE-2026-61445 9.9 PraisonAI: AICoder root RCE via unsanitized tool calls
Same package: praisonai CVE-2026-47392 9.9 praisonaiagents: RCE via Python sandbox bypass
Same package: praisonai GHSA-vmmj-pfw7-fjwp 9.9 praisonai: sandbox escape gives RCE via codeMode tool
Same package: praisonai GHSA-vc46-vw85-3wvm 9.8 PraisonAI: RCE via malicious workflow YAML execution
Same package: praisonai