A vulnerability has been found in MervinPraison praisonai-platform up to 0.1.3 and classified as critical. This vulnerability affects the function get/update/delete/get_stats of the component CRUD endpoint. The manipulation of the argument workspace_id/project_id leads to improper control of resource identifiers.

This vulnerability is traded as CVE-2026-47418. It is possible to initiate the attack remotely. There is no exploit available.