CVE-2026-108110
MOVO through 0.2.3 Authorization Bypass via Document Endpoints
CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th
MOVO through 0.2.3 contains an authorization bypass vulnerability in the chat-api document endpoints that allows authenticated users to access other users' stored objects by supplying arbitrary object paths. Attackers who know a target's object path can send it to /api/documents/fetch or /api/documents/save-blueprint to read private documents and overwrite presentation blueprints.
| CWE | CWE-639 |
| Vendor | himovo |
| Product | movo |
| Published | Oct 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for himovo movo
Be the first to know when new medium vulnerabilities affecting himovo movo are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
himovo / MOVO
0.1.0 โค 0.2.3
References
hackmd.io: https://hackmd.io/HfAnJ59RQuSNLYmNGkAKog github.com: https://github.com/himovo/movo/blob/v0.2.3/services/chat-api/app/api/endpoints/documents.py#L237-L274 github.com: https://github.com/himovo/movo/blob/v0.2.3/services/chat-api/app/api/endpoints/documents.py#L91-L109 github.com: https://github.com/himovo/movo vulncheck.com: https://www.vulncheck.com/advisories/movo-through-0.2.3-authorization-bypass-via-document-endpoints
Credits
HaiND from the Post and Telecommunication Institute of Technology