Beveiligingsadvies

CVE-2026-82284

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-28 16:19:03
Laatst bijgewerkt 2026-08-28 20:23:13
Toegewezen door VulnCheck
CVSS-score 8.6
Status PUBLISHED

Beschrijving

Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' conversation histories including private knowledge base content, delete arbitrary chats, and inject fabricated messages into other users' conversations.