GHSA-2mxf-m4gh-hj3gHighCVSS 7.1

Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated...

Published
August 28, 2026
Last Modified
August 28, 2026

🔗 CVE IDs covered (1)

📋 Description

Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite system prompts affecting all brain users.

🔗 References (6)