top of page
perceptive_background_267k.jpg

Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/ans…

Published:

28 August 2026 at 00:00:00

Alert date:

28 August 2026 at 23:18:32

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Data Breach & Exfiltration

Quivr versions through 0.0.322 contain a broken object-level authorization (BOLA/IDOR) vulnerability in three chat-related API endpoints: GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer. The application fails to verify that the authenticated requester actually owns the targeted chat resource. As a result, any authenticated attacker can read other users' full conversation histories, including content from private knowledge bases, delete arbitrary chats belonging to other users, and inject fabricated messages into other users' conversations. The vulnerability affects all versions up to and including 0.0.322. The issue is tracked as CVE-2026-82284 and has been reported via GitHub issues and documented by VulnCheck. Remediation requires implementing proper chat ownership checks on all affected endpoints.

Technical details

Mitigation steps:

Affected products:

Quivr

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page