VYPR
High severity7.1NVD Advisory· Published Aug 28, 2026

CVE-2026-82280

CVE-2026-82280

Description

Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite system prompts affecting all brain users.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • QuivrHQ/Quivrreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=0.0.322

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.