An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system to view, modify, and delete chats created by an Admin. This can lead to unauthorized access to sensitive information, loss of data integrity, and potential compliance violations.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-6945 An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system to view, modify, and delete chats created by an Admin. This can lead to unauthorized access to sensitive information, loss of data integrity, and potential compliance violations.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 15 Oct 2025 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 15 Oct 2025 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862

Tue, 01 Apr 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Onyx
Onyx onyx
CPEs cpe:2.3:a:onyx:onyx:0.3.94:*:*:*:*:*:*:*
Vendors & Products Onyx
Onyx onyx
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Thu, 20 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system to view, modify, and delete chats created by an Admin. This can lead to unauthorized access to sensitive information, loss of data integrity, and potential compliance violations.
Title Improper Access Control in danswer-ai/danswer
Weaknesses CWE-284
References
Metrics cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2025-10-15T12:49:51.871Z

Reserved: 2024-08-13T18:40:30.797Z

Link: CVE-2024-7767

cve-icon Vulnrichment

Updated: 2025-03-20T13:09:19.062Z

cve-icon NVD

Status : Modified

Published: 2025-03-20T10:15:37.007

Modified: 2025-10-15T13:15:52.630

Link: CVE-2024-7767

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.