CVE-2026-82280
Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite system prompts affecting all brain users.
- Published Aug 28, 2026
- CVSS 7.1 high
- 0.3% chance of exploitation in the next 30 days (EPSS)