Impact
An attacker can invoke the processMessage function within TinyAGI's Message API Endpoint without passing proper authorization, because the endpoint lacks enforcement of required access controls. The weakness is identified as missing authorization and missing access control (CWE‑862/CWE‑863). When successful, the attacker can submit arbitrary messages to the service, potentially leading to unauthorized data manipulation or exposure.
Affected Systems
The vulnerability is present in TinyAGI version 0.0.20, the only version explicitly referenced in the advisory. No other affected releases are listed.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate impact, with the exploit classified as remote. EPSS data are not available and the issue is not listed in the CISA KEV catalog. The description notes missing authorization. Based on the description, it is inferred that an attacker can trigger the endpoint from any network reachability to the system, provided the service is exposed externally. Public reports confirm that an exploit exists has been disclosed.
OpenCVE Enrichment