PT-2026-83307 · Quivr · Quivr

·

CVE-2026-82284

·

Published

2026-08-28

·

Updated

2026-08-28

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Quivr versions prior to 0.0.323
Description Authenticated attackers can read other users' conversation histories, including private knowledge base content, delete arbitrary chats, and inject fabricated messages into other users' conversations. This occurs because the application fails to validate chat ownership in the following endpoints:
  • 'GET /chat/{chat id}/history'
  • 'DELETE /chat/{chat id}'
  • 'POST /chat/{chat id}/question/answer'
The vulnerable variable is chat id.
Recommendations Update to a version newer than 0.0.322.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82284

Affected Products

Quivr