云虫漏洞情报

CVE-2026-82271 - R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename conversations and append messages to other users' conversation histories, corrupting state and injecting malicious content. - 漏洞详情

漏洞编号:CVE-2026-82271

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-82271

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-639

发布/更新时间:2026-08-28 / 2026-08-28

漏洞描述

R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations. Attackers can supply arbitrary conversation identifiers to rename conversations and append messages to other users' conversation histories, corrupting state and injecting malicious content.

相关链接

相关漏洞

« 返回首页