CVE-2025-0740

An Improper Access Control vulnerability has been found in EmbedAI

 2.1 and below. This vulnerability allows an authenticated attacker to obtain chat messages belonging to other users by changing the CHAT_ID of the endpoint "/embedai/chats/load_messages?chat_id=<CHAT_ID>".
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
INCIBECNA
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CISA-ADPADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 14%