Vulnerability Description
GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logged-in user who knows a shared AI assistant's identifier may view and/or tamper the other user's threads/messages.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-25083?
CVE-2026-25083 is a vulnerability with a CVSS score of 8.3 (HIGH). GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logged-in user who knows a shared AI assistant's identifier may view and/or tamper t...
How severe is CVE-2026-25083?
CVE-2026-25083 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-25083?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.