CVE-2026-82280: Quivr Prompt Endpoints Missing Ownership Validation
Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite system prompts affecting all brain users.
Affected Software
Event History
Frequently Asked Questions
Who is most exposed to this issue?
Deployments where prompts are shared through brains are most exposed. A user with read-only access to a shared brain may be able to obtain prompt identifiers and overwrite system prompts used by all users of that brain.
What access does an attacker need?
The attacker must be authenticated and have at least read-only access to a shared brain containing exposed prompt identifiers. No user interaction is required.
Which versions are affected?
Quivr through version 0.0.322 is affected.
What is the impact of successful exploitation?
An attacker can modify prompts they do not own by supplying their identifiers to the affected prompt endpoints. Overwriting a system prompt can affect all users of the associated brain.