CVE-2026-25083: High severity GROWI GROWI vulnerability
Published Mar 16, 2026
·Updated
GROWI OpenAI thread/message API endpoints do not perform authorization. Affected are v7.4.5 and earlier versions. A logged-in user who knows a shared AI assistant's identifier may view and/or tamper the other user's threads/messages.
Affected Software
1 affected component
GROWI GROWI<7.4.5
Event History
Mar 16, 2026
CVE Published
via MITRE·06:47 AM
Data Sourced
via MITRE·06:47 AM
DescriptionSeverity
Data Sourced
via NVD·02:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25083?
CVE-2026-25083 has a critical severity due to its potential for unauthorized access to user threads and messages.
2
How do I fix CVE-2026-25083?
To fix CVE-2026-25083, upgrade to version 7.4.6 or later where the authorization issues have been resolved.
3
Which versions of GROWI are affected by CVE-2026-25083?
CVE-2026-25083 affects GROWI versions v7.4.5 and earlier.
4
What type of attack does CVE-2026-25083 enable?
CVE-2026-25083 enables unauthorized users to view or tamper with personal threads and messages of other users.
5
Is CVE-2026-25083 a local or remote vulnerability?
CVE-2026-25083 is considered a remote vulnerability as it can be exploited by logged-in users on the platform.