CVE-2026-82280
Quivr Prompt Endpoints Missing Ownership Validation
CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th
Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite system prompts affecting all brain users.
| CWE | CWE-639 |
| Vendor | quivrhq |
| Product | quivr |
| Published | Aug 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for quivrhq quivr
Be the first to know when new high vulnerabilities affecting quivrhq quivr are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None
Affected Versions
QuivrHQ / quivr
0 โค 0.0.322
References
github.com: https://github.com/QuivrHQ/quivr/issues/3698 github.com: https://github.com/QuivrHQ/quivr github.com: https://github.com/QuivrHQ/quivr/blob/v0.0.322/backend/api/quivr_api/modules/prompt/controller/prompt_routes.py vulncheck.com: https://www.vulncheck.com/advisories/quivr-prompt-endpoints-missing-ownership-validation
Credits
๐ George Chen