Executive brief
Quivr is a retrieval-augmented generation (RAG) platform used to integrate AI capabilities into applications. Authenticated users can access, delete, and manipulate other users' chat conversations and private knowledge bases due to missing ownership checks, allowing attackers to read sensitive business data, destroy chat records, and impersonate users in conversations.
Technical details
This vulnerability is a missing authorization check (CWE-862) affecting the chat management API endpoints in Quivr through version 0.0.322. The GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints fail to validate that the authenticated user owns the referenced chat before granting access or performing operations. An authenticated attacker can enumerate or guess chat IDs and read other users' conversation histories (including content from private knowledge bases), delete arbitrary chats, or inject false messages into other users' conversations. The vulnerability requires valid authentication but no elevated privileges. Patches are expected in versions after 0.0.322.
Affected products
- Quivr Quivr through 0.0.322
Timeline
- 2026-08-28: disclosed