Improper Access Control in EmbedAI Affects User Chat Functionality
CVE-2025-0741
What is CVE-2025-0741?
An Improper Access Control vulnerability has been identified in EmbedAI versions 2.1 and below. This security flaw allows an authenticated attacker to manipulate the 'chat_id' parameter in a POST request to the '/embedai/chats/send_message' endpoint. As a result, attackers can send messages within other users' chat sessions, potentially leading to unauthorized access to sensitive communications and disrupting user experiences. Addressing this vulnerability is crucial for ensuring the integrity and security of user interactions in the platform.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EmbedAI 0 < 2.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
