🛡️ PraisonAI Workspace Isolation Flaw Allows Cross-Tenant Access
Upgrade PraisonAI Platform to version 0.1.4 and investigate possible cross-workspace access. Shared multi-tenant deployments should treat this as a high-priority fix.
PraisonAI Platform versions prior to 0.1.4 contain a systemic object-level authorization flaw in workspace-scoped REST routes. Authenticated users can access, modify, or delete objects from other workspaces by supplying victim object UUIDs. This is a HIGH vulnerability with CVSS 8.8.
🔗 Read more 🔗
Source: NVD
🔐 PraisonAI Platform JWT Secret Flaw Enables Account Takeover
PraisonAI Platform administrators should upgrade to version 0.1.4 immediately. Prioritize exposed deployments because attackers who obtain the default secret can bypass authentication and access user accounts.
PraisonAI Platform versions prior to 0.1.4 contain an insecure default cryptographic key vulnerability. The platform uses a hardcoded JWT signing secret when PLATFORM_JWT_SECRET is unset, allowing attackers to mint tokens and authenticate as existing users including workspace owners and admins. This is a CRITICAL vulnerability with CVSS 9.8.
🔗 Read more 🔗
Source: NVD
🚨 PraisonAI Platform Member Removal Authorization Bypass
PraisonAI Platform users should upgrade to version 0.1.4 as soon as possible. Review workspace membership changes after patching if the platform was accessible to multiple users.
PraisonAI Platform versions prior to 0.1.4 contain an authorization bypass affecting workspace member removal. Any workspace member can remove other members, including workspace owners, because the endpoint lacks proper role checks. This is a HIGH vulnerability with CVSS 8.1.
🔗 Read more 🔗
Source: NVD
💥 PraisonAI Platform Critical Workspace Access Control Failure
Upgrade PraisonAI Platform to version 0.1.4 immediately, especially for internet-exposed deployments. Review logs for suspicious cross-workspace activity or unexpected privilege changes.
PraisonAI Platform versions prior to 0.1.4 contain critical workspace authorization flaws that allow cross-workspace resource access and privilege escalation. Attackers can access, modify, or delete resources and perform administrative actions because workspace and role checks are not properly enforced. This is a CRITICAL vulnerability with CVSS 9.4.
🔗 Read more 🔗
Source: NVD
🔗 PraisonAI Dependency API IDOR Exposes Workspace Boundaries
Upgrade PraisonAI Platform to version 0.1.4 and verify workspace data isolation. Teams should review dependency changes if untrusted users could access the platform.
PraisonAI Platform versions prior to 0.1.4 contain an Insecure Direct Object Reference vulnerability in dependency endpoints. Attackers can use issue and dependency identifiers without proper workspace ownership validation, allowing unauthorized cross-workspace relationships to be created. This is a HIGH vulnerability with CVSS 8.1.
🔗 Read more 🔗
Source: NVD
👑 PraisonAI Workspace Members Can Escalate to Owner
PraisonAI Platform administrators should deploy version 0.1.4 immediately and review recent role changes. The issue can allow authenticated users to gain unauthorized administrative control.
PraisonAI Platform versions prior to 0.1.4 contain a broken access control vulnerability allowing low-privilege members to escalate their roles to owner. Administrative routes do not enforce required privilege levels, enabling users to change roles and take over workspace management. This is a HIGH vulnerability with CVSS 8.8.
🔗 Read more 🔗
Source: NVD
⚙️ PraisonAI Module Loader Flaw Enables Unsafe Execution
PraisonAI users should upgrade to version 4.6.40 and review configurations that allow custom module paths. Restrict untrusted configuration input until the update is applied.
PraisonAI versions prior to 4.6.40 contain an unsafe module loading vulnerability in agents_generator.py. Unvalidated module paths from YAML configuration can be executed because protection checks were missing. This is a HIGH vulnerability with CVSS 8.1.
🔗 Read more 🔗
Source: NVD
📁 PraisonAI File Write Bug Allows Arbitrary Path Writes
PraisonAI users should upgrade to version 4.6.40 and limit agent access to sensitive filesystem locations. Review files created by agents that processed untrusted web content.
PraisonAI versions prior to 4.6.40 contain a path validation flaw where attacker-controlled webpage metadata can cause agents to write files to arbitrary locations. The write_file function skips path validation when workspace is unset. This is a HIGH vulnerability with CVSS 7.1.
🔗 Read more 🔗
Source: NVD
🔥 React Server Components DoS Bug Drives Excessive CPU Usage
Applications using affected React Server Components packages should update to fixed versions as soon as possible. Prioritize internet-facing services because crafted requests can impact availability.
A denial of service vulnerability affects react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack versions listed in the advisory. Specially crafted HTTP requests to server function endpoints can trigger excessive CPU usage. This is a HIGH vulnerability with CVSS 7.5.
🔗 Read more 🔗
Source: NVD
🗄️ BigQuery Forecast Tool SQL Injection Breaks Data Controls
Organizations using the affected MCP Toolbox component should patch promptly and review query access activity. Treat this as urgent because attackers may bypass configured data boundaries.
A SQL injection and security boundary bypass vulnerability exists in the prebuilt BigQuery forecasting tool of googleapis/mcp-toolbox. Client-controlled parameters are inserted into generated queries without proper escaping, allowing attackers to bypass allowed dataset restrictions and access unauthorized BigQuery tables. This is a HIGH vulnerability with CVSS 8.6.
🔗 Read more 🔗
Source: NVD
🐳 BuildKit Git Checkout Flaw Can Trigger Host Commands
BuildKit users should update affected components and avoid processing untrusted Git sources until patched. CI/CD environments using external repositories should be prioritized.
BuildKit custom frontends or clients using the raw low-level API can be affected when git.checkoutbundle=true is used with a malicious Git source. The issue could lead to crafted command invocation on the host. This is a HIGH vulnerability with CVSS 7.3.
🔗 Read more 🔗
Source: NVD
📂 ShareFile Storage Zones Path Traversal Exposes Server Files
ShareFile administrators should apply the vendor updates immediately and limit administrative access while remediation is pending. Review filesystem activity after patching.
Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2 contain a path traversal vulnerability. An authenticated administrative user can read arbitrary files, write files to arbitrary directories, or determine whether files exist on the server filesystem. This is a HIGH vulnerability with CVSS 8.7.
🔗 Read more 🔗
Source: NVD