A vulnerability, which was classified as critical, was found in MervinPraison praisonai-platform up to 0.1.3. This affects the function require_workspace_member of the component Comment Endpoints. Executing a manipulation of the argument workspace_id/issue_id can lead to improper control of resource identifiers.

This vulnerability appears as CVE-2026-47417. The attack may be performed from remote. There is no available exploit.