GHSA-2mxf-m4gh-hj3gHighCVSS 7.1
Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated...
🔗 CVE IDs covered (1)
📋 Description
Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite system prompts affecting all brain users.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-82280
- https://github.com/QuivrHQ/quivr/issues/3698
- https://github.com/QuivrHQ/quivr
- https://github.com/QuivrHQ/quivr/blob/v0.0.322/backend/api/quivr_api/modules/prompt/controller/prompt_routes.py
- https://www.vulncheck.com/advisories/quivr-prompt-endpoints-missing-ownership-validation
- https://github.com/advisories/GHSA-2mxf-m4gh-hj3g