CVE-2026-85669
EUVD-2026-7112504.09.2026, 15:17
potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpoint. Authenticated attackers can write arbitrary file changes into other users' conversations by supplying their conversation IDs, allowing unauthorized modification of pending changes.EnginsightAwaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration