Impact
The vulnerability is a missing ownership check on the POST /conversations/{conversation_id}/code‑changes/sync endpoint. An authenticated attacker can supply any conversation identifier to inject arbitrary file changes, effectively tampering with pending changes belonging to another user. This flaw represents an authorization failure (CWE‑862) that can lead to unauthorized data modification, possible leakage of confidential code, and disruption of collaborative workflows.
Affected Systems
The affected product is potpie, developed by potpie‑ai, with all releases up to and including version 2.0.0 susceptible to this flaw. No other vendors or product variants are currently known to be affected according to the CNA. The version selector "potpie:potpie" captures the entire product line.
Risk and Exploitability
The CVSS score of 7.1 denotes a high severity impact for authenticated users. The EPSS score is not provided, and the issue is not currently listed in the CISA KEV catalog. Attackors need valid credentials to exploit the API endpoint and can target any conversation ID, making the vulnerability relatively easy to trigger if the system is accessible over the network. Hence, the risk of exploitation is moderate to high for an unpatched system.
OpenCVE Enrichment