CVE-2026-82280

Summary

Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite system prompts affecting all brain users.

Affected Software

VendorProductVersion RangeStatus
QuivrHQquivr0 <= 0.0.322affected

Weaknesses

  • CWE-639: Authorization Bypass Through User-Controlled Key

References