Impact
Quivr versions up to 0.0.322 allow authenticated users to modify any prompt when provided only a prompt identifier. The lack of ownership validation means that any user can read prompt IDs and overwrite system prompts, potentially impacting the integrity of shared brain data and enabling malicious actors to embed harmful content or alter AI behavior. The vulnerability is specifically related to CWE‑639, which concerns insufficient validation of ownership or access control in the application logic.
Affected Systems
The affected product is QuivrHQ’s Quivr application, with all releases through and including 0.0.322 vulnerable. No specific sub‑component versions beyond this are noted.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk to confidentiality, integrity, and availability. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, but the attack vector is inferred to require an authenticated user with read‑only access to a shared brain. An attacker who can discover prompt identifiers can overwrite any prompt, including system‑level prompts that affect all users of that brain. The exploit does not provide remote code execution or privilege escalation beyond data tampering, yet it can have significant operational impact.
OpenCVE Enrichment