Vulnerability Description
Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite system prompts affecting all brain users.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/QuivrHQ/quivr
- https://github.com/QuivrHQ/quivr/blob/v0.0.322/backend/api/quivr_api/modules/pro
- https://github.com/QuivrHQ/quivr/issues/3698
- https://www.vulncheck.com/advisories/quivr-prompt-endpoints-missing-ownership-va
- https://github.com/The-Vibe-Company/Quivr/issues/3698
FAQ
What is CVE-2026-82280?
CVE-2026-82280 is a vulnerability with a CVSS score of 7.1 (HIGH). Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read expose...
How severe is CVE-2026-82280?
CVE-2026-82280 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-82280?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.