PT-2026-83307 · Quivr · Quivr
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Quivr versions prior to 0.0.323
Description
Authenticated attackers can read other users' conversation histories, including private knowledge base content, delete arbitrary chats, and inject fabricated messages into other users' conversations. This occurs because the application fails to validate chat ownership in the following endpoints:
- 'GET /chat/{chat id}/history'
- 'DELETE /chat/{chat id}'
- 'POST /chat/{chat id}/question/answer'
The vulnerable variable is
chat id.Recommendations
Update to a version newer than 0.0.322.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quivr