Improper Access Control in EmbedAI Affects User Chat Functionality
CVE-2025-0741

5.8MEDIUM

Key Information:

Vendor
Embedai
Status
Embedai
Vendor
CVE Published:
30 January 2025

Summary

An Improper Access Control vulnerability has been identified in EmbedAI versions 2.1 and below. This security flaw allows an authenticated attacker to manipulate the 'chat_id' parameter in a POST request to the '/embedai/chats/send_message' endpoint. As a result, attackers can send messages within other users' chat sessions, potentially leading to unauthorized access to sensitive communications and disrupting user experiences. Addressing this vulnerability is crucial for ensuring the integrity and security of user interactions in the platform.

Affected Version(s)

EmbedAI 0 < 2.1

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

David Utón Amaya (m3n0sd0n4ld)
.