File Modification Vulnerability in Potpie Software
CVE-2026-85669
7.1HIGH
What is CVE-2026-85669?
Potpie versions through 2.0.0 are susceptible to a vulnerability where authenticated users can manipulate other users' conversations. The issue lies in the improper validation of user ownership on the endpoint handling code changes, specifically the POST /conversations/{conversation_id}/code-changes/sync path. By exploiting this flaw, attackers can introduce arbitrary file modifications into conversations that do not belong to them by leveraging valid conversation IDs, leading to potential unauthorized alterations of pending changes.
Affected Version(s)
potpie 0 <= 2.0.0
