Junglewise Threat Intelligence

CVE-2026-25083: GROWI missing authorization in OpenAI thread and message API

CVE-2026-25083 · Severity: high · CVSS 8.3 · Published 2026-03-16

Technologies: GROWI, Inc. GROWI.

Executive brief

GROWI is an open-source wiki and collaboration platform. A security flaw in its AI assistant integration allows logged-in users to view or modify the private chat threads and messages of other users. This could lead to the exposure of sensitive internal discussions or the unauthorized alteration of shared information if an attacker knows the identifier of a shared AI assistant.

Technical details

A missing authorization vulnerability (CWE-862) exists in the OpenAI thread and message API endpoints of GROWI. The root cause is a failure to verify if the requesting user has permission to access or modify a specific thread or message. An authenticated attacker with network access can exploit this by supplying the identifier of a shared AI assistant to interact with data belonging to other users. This allows for unauthorized viewing (Confidentiality) and tampering (Integrity) of AI-related communications. The issue is resolved in GROWI v7.4.6.

Affected products

  • GROWI, Inc. GROWI v7.4.5 and earlier

Timeline

  • 2026-03-16: disclosed
  • 2026-03-16: advisory
  • 2026-03-16: patched: Fixed in v7.4.6

References