๐Ÿ” CVE Alert

CVE-2026-108110

MEDIUM 6.8

MOVO through 0.2.3 Authorization Bypass via Document Endpoints

CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th

MOVO through 0.2.3 contains an authorization bypass vulnerability in the chat-api document endpoints that allows authenticated users to access other users' stored objects by supplying arbitrary object paths. Attackers who know a target's object path can send it to /api/documents/fetch or /api/documents/save-blueprint to read private documents and overwrite presentation blueprints.

CWE CWE-639
Vendor himovo
Product movo
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for himovo movo

Be the first to know when new medium vulnerabilities affecting himovo movo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

himovo / MOVO
0.1.0 โ‰ค 0.2.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/HfAnJ59RQuSNLYmNGkAKog github.com: https://github.com/himovo/movo/blob/v0.2.3/services/chat-api/app/api/endpoints/documents.py#L237-L274 github.com: https://github.com/himovo/movo/blob/v0.2.3/services/chat-api/app/api/endpoints/documents.py#L91-L109 github.com: https://github.com/himovo/movo vulncheck.com: https://www.vulncheck.com/advisories/movo-through-0.2.3-authorization-bypass-via-document-endpoints

Credits

HaiND from the Post and Telecommunication Institute of Technology