CVE-2025-0740

An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain chat messages belonging to other users by changing the “CHAT_ID” of the endpoint "/embedai/chats/load_messages?chat_id=<CHAT_ID>".
Configurations

Configuration 1 (hide)

cpe:2.3:a:thesamur:embedai:*:*:*:*:*:*:*:*

History

10 Oct 2025, 16:41

Type Values Removed Values Added
Summary
  • (es) Se ha detectado una vulnerabilidad de control de acceso inadecuado en EmbedAI 2.1 y versiones anteriores. Esta vulnerabilidad permite a un atacante autenticado obtener mensajes de chat pertenecientes a otros usuarios modificando el “CHAT_ID” del endpoint "/embedai/chats/load_messages?chat_id=".
CPE cpe:2.3:a:thesamur:embedai:*:*:*:*:*:*:*:*
First Time Thesamur embedai
Thesamur
References () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-embedai - () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-embedai - Third Party Advisory

30 Jan 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-30 11:15

Updated : 2025-10-10 16:41


NVD link : CVE-2025-0740

Mitre link : CVE-2025-0740

CVE.ORG link : CVE-2025-0740


JSON object : View

Products Affected

thesamur

  • embedai
CWE
CWE-284

Improper Access Control