CVE-2026-25083
CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th
GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logged-in user who knows a shared AI assistant's identifier may view and/or tamper the other user's threads/messages.
| Vendor | growi, inc. |
| Product | growi |
| Published | Mar 16, 2026 |
| Last Updated | Mar 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for growi, inc. growi
Be the first to know when new high vulnerabilities affecting growi, inc. growi are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L Affected Versions
GROWI, Inc. / GROWI
v7.4.5 and earlier