Improper Access Control in EmbedAI Affects User Subscription Information
CVE-2025-0739
8.6HIGH
What is CVE-2025-0739?
An Improper Access Control vulnerability exists in EmbedAI versions up to 2.1. This flaw enables authenticated attackers to access and display subscription information of other users by manipulating the 'SUBSCRIPTION_ID' parameter in the endpoint '/demos/embedai/subscriptions/show/<SUBSCRIPTION_ID>'. This could potentially lead to unauthorized disclosure of sensitive user data.
Affected Version(s)
EmbedAI 0 < 2.1