VYPR
High severity8.1NVD Advisory· Published Aug 28, 2026

CVE-2026-82284

CVE-2026-82284

Description

Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' conversation histories including private knowledge base content, delete arbitrary chats, and inject fabricated messages into other users' conversations.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • QuivrHQ/Quivrreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=0.0.322

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.