{"id":"CVE-2026-82280","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-82280","summary":"Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains…","details":"Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite system prompts affecting all brain users.","published":"2026-08-28T20:20:19.213","modified":"2026-08-28T20:20:19.213","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/QuivrHQ/quivr"},{"type":"WEB","url":"https://github.com/QuivrHQ/quivr/blob/v0.0.322/backend/api/quivr_api/modules/prompt/controller/prompt_routes.py"},{"type":"WEB","url":"https://github.com/QuivrHQ/quivr/issues/3698"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/quivr-prompt-endpoints-missing-ownership-validation"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T20:20:19.213"}}