Security Advisory

CVE-2025-51865

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-22 00:00:00
Last updated 2025-07-22 15:40:12
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to gain sensitvie information via enumerating thread keys in the URL.