File Modification Vulnerability in Potpie Software
CVE-2026-85669

7.1HIGH

Key Information:

Vendor

Potpie-ai

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-85669?

Potpie versions through 2.0.0 are susceptible to a vulnerability where authenticated users can manipulate other users' conversations. The issue lies in the improper validation of user ownership on the endpoint handling code changes, specifically the POST /conversations/{conversation_id}/code-changes/sync path. By exploiting this flaw, attackers can introduce arbitrary file modifications into conversations that do not belong to them by leveraging valid conversation IDs, leading to potential unauthorized alterations of pending changes.

Affected Version(s)

potpie 0 <= 2.0.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.