CVE-2026-58653EPSS p5.5%
CVE-2026-58653CVE-2026-58653
Description
PraisonAI before 0.1.7 fails to validate that project_id in issue create and update request bodies belongs to the URL workspace. An attacker can create issues referencing projects from other workspaces, causing cross-tenant data pollution in project statistics aggregation without workspace constraints.
Scoring
| CVSS | 4.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| EPSS | 0.16% probability of exploitation · percentile 5.5% · 2026-08-16T12:03:43Z |
| Last modified | 2026-07-02 |