Impact
Wukong AICRM up to the 20260610 release contains a missing authorization check that lets any logged‑in user send messages to chat sessions belonging to other users. By providing an arbitrary session identifier in the POST /chat/send request, an attacker can append messages and receive assistant replies generated from the target’s recent conversation history. The flaw effectively grants the attacker read access to the victim’s chat content and the ability to modify that content, exposing sensitive dialogue and potentially corrupting the chat data. The weakness is classified as CWE‑639, an authorization bypass.
Affected Systems
The vulnerability exists in the WuKongOpenSource Wukong AICRM product, specifically in versions released through and including 20260610. No other vendors or versions are currently listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, reflecting that the flaw requires the attacker to be an authenticated user with access to the application. Exploitation does not rely on elevated privileges beyond normal user rights and does not need network isolation, meaning any legitimate user within the system can abuse the flaw. The EPSS score is unavailable, and the vulnerability is not catalogued in CISA’s KEV list, but the straightforward nature of the exploit and its potential for privacy disclosure give it practical risk in environments where sensitive conversations occur.
OpenCVE Enrichment