


Perceptive Security
SOC/SIEM Consultancy

Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/ans…
Published:
28 August 2026 at 00:00:00
Alert date:
28 August 2026 at 23:18:32
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Data Breach & Exfiltration
Quivr versions through 0.0.322 contain a broken object-level authorization (BOLA/IDOR) vulnerability in three chat-related API endpoints: GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer. The application fails to verify that the authenticated requester actually owns the targeted chat resource. As a result, any authenticated attacker can read other users' full conversation histories, including content from private knowledge bases, delete arbitrary chats belonging to other users, and inject fabricated messages into other users' conversations. The vulnerability affects all versions up to and including 0.0.322. The issue is tracked as CVE-2026-82284 and has been reported via GitHub issues and documented by VulnCheck. Remediation requires implementing proper chat ownership checks on all affected endpoints.
Technical details
Mitigation steps:
Affected products:
Quivr
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82284
https://github.com/QuivrHQ/quivr
https://github.com/QuivrHQ/quivr/blob/v0.0.322/backend/api/quivr_api/modules/chat/controller/chat_routes.py
https://github.com/QuivrHQ/quivr/issues/3697
https://www.vulncheck.com/advisories/quivr-chat-endpoints-missing-ownership-validation
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
