Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
VoltAgent Memory API Handlers Missing Ownership Checks
Vulnerability Description
VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations. Attackers can read, modify, and delete arbitrary conversations and messages by supplying caller-controlled identifiers to memory endpoints.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
VoltAgent 授权问题漏洞
Vulnerability Description
VoltAgent是VoltAgent组织的一款数据库管理工具。 VoltAgent 2.1.20及之前版本存在授权问题漏洞,该漏洞源于内存API处理程序中未验证会话所有权,可能允许已认证用户通过提供调用者控制的标识符访问其他用户的会话,进而读取、修改和删除任意会话和消息。
CVSS Information
N/A
Vulnerability Type
N/A