CVE-2026-58653: PraisonAI - Authorization Bypass via Unvalidated project_id in Issue Create/Update
PraisonAI before 0.1.7 fails to validate that projectid in issue create and update request bodies belongs to the URL workspace. An attacker can create issues referencing projects from other workspaces, causing cross-tenant data pollution in project statistics aggregation without workspace constraints.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PraisonAIto a version that resolves this vulnerability.Fixed in 0.1.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58653?
CVE-2026-58653 has a medium severity score of 4.3.
How do I fix CVE-2026-58653?
To fix CVE-2026-58653, update PraisonAI to version 0.1.7 or later.
What does CVE-2026-58653 affect?
CVE-2026-58653 affects versions of PraisonAI prior to version 0.1.7 that do not validate project_id in issue creation and updates.
What type of vulnerability is CVE-2026-58653?
CVE-2026-58653 is an authorization bypass vulnerability that allows attackers to access cross-tenant data.
What could an attacker do with CVE-2026-58653?
An attacker could exploit CVE-2026-58653 to create issues referencing projects from other workspaces, leading to data pollution.