CVE-2026-82284
- EPSS 0.24%
- Veröffentlicht 28.08.2026 16:19:03
- Zuletzt bearbeitet 23.09.2026 17:17:46
Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' conversation histories includ...
CVE-2026-82280
- EPSS 0.2%
- Veröffentlicht 28.08.2026 16:19:00
- Zuletzt bearbeitet 23.09.2026 17:17:46
Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite system prompts ...
CVE-2024-6583
- EPSS 0.58%
- Veröffentlicht 20.03.2025 10:10:23
- Zuletzt bearbeitet 15.07.2025 15:55:29
A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker to upload files to arbitrary paths in an S3 bucket by manipulating the file path in the upload request.
CVE-2024-6229
- EPSS 0.34%
- Veröffentlicht 07.07.2024 16:15:02
- Zuletzt bearbeitet 21.11.2024 09:49:14
A stored cross-site scripting (XSS) vulnerability exists in the 'Upload Knowledge' feature of stangirard/quivr, affecting the latest version. Users can upload files via URL, which allows the insertion of malicious JavaScript payloads. These payloads ...
CVE-2024-5885
- EPSS 0.55%
- Veröffentlicht 27.06.2024 19:15:17
- Zuletzt bearbeitet 21.11.2024 09:48:31
stangirard/quivr version 0.0.236 contains a Server-Side Request Forgery (SSRF) vulnerability. The application does not provide sufficient controls when crawling a website, allowing an attacker to access applications on the local network. This vulnera...
CVE-2024-4851
- EPSS 0.58%
- Veröffentlicht 06.06.2024 19:16:02
- Zuletzt bearbeitet 21.11.2024 09:43:43
A Server-Side Request Forgery (SSRF) vulnerability exists in the stangirard/quivr application, version 0.0.204, which allows attackers to access internal networks. The vulnerability is present in the crawl endpoint where the 'url' parameter can be ma...