{"id":"CVE-2026-58653","aliases":["GHSA-2fjj-qqg8-fg7x"],"url":"https://o3.security/vulnerability/CVE-2026-58653","summary":"PraisonAI - Authorization Bypass via Unvalidated project_id in Issue Create/Update","details":"PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL workspace. An attacker can create issues referencing projects from other workspaces, causing cross-tenant data pollution in project statistics aggregation without workspace constraints.","published":"2026-07-02T12:34:00.914Z","modified":"2026-08-12T03:51:26.048098048Z","cvss":null,"epss":{"score":0.00264,"percentile":0.18362,"asOf":"2026-09-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"praisonai-platform","fixedVersion":"0.1.8"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58653.json"},{"type":"ADVISORY","url":"https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-2fjj-qqg8-fg7x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-58653"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/praisonai-authorization-bypass-via-unvalidated-project-id-in-issue-create-update"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.048098048Z"}}