Improper Access Control in EmbedAI Affects User Chat Functionality
CVE-2025-0741
5.8MEDIUM
What is CVE-2025-0741?
An Improper Access Control vulnerability has been identified in EmbedAI versions 2.1 and below. This security flaw allows an authenticated attacker to manipulate the 'chat_id' parameter in a POST request to the '/embedai/chats/send_message' endpoint. As a result, attackers can send messages within other users' chat sessions, potentially leading to unauthorized access to sensitive communications and disrupting user experiences. Addressing this vulnerability is crucial for ensuring the integrity and security of user interactions in the platform.
Affected Version(s)
EmbedAI 0 < 2.1