CVE-2026-61440: PraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints
PraisonAI Platform before 0.1.9 fails to properly authorize label and issue-label mutations, allowing workspace members to rename and recolor shared labels and add or remove labels on owner-created issues. Attackers with workspace member privileges can exploit PATCH and POST/DELETE endpoints to alter shared label taxonomy and manipulate issue-label associations without owner or admin authorization.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PraisonAI Platformto a version that resolves this vulnerability.Fixed in 0.1.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61440?
CVE-2026-61440 has a severity score of 7.1, categorized as high.
How do I fix CVE-2026-61440?
To fix CVE-2026-61440, upgrade the PraisonAI Platform to version 0.1.9 or later.
What type of vulnerability is CVE-2026-61440?
CVE-2026-61440 is an authorization bypass vulnerability affecting label endpoints.
Who is affected by CVE-2026-61440?
CVE-2026-61440 affects users with workspace member privileges on the PraisonAI Platform.
What actions can attackers perform due to CVE-2026-61440?
Attackers exploiting CVE-2026-61440 can rename, recolor, and manipulate shared labels in issues.