Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
potpie through 2.0.0 Missing Ownership Check via code-changes sync
Vulnerability Description
potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpoint. Authenticated attackers can write arbitrary file changes into other users' conversations by supplying their conversation IDs, allowing unauthorized modification of pending changes.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
potpie.ai potpie 授权问题漏洞
Vulnerability Description
potpie.ai potpie是potpie.ai组织的一个基于代码库生成定制AI代理的平台。 potpie.ai potpie 2.0.0及之前版本存在授权问题漏洞,该漏洞源于未验证POST /conversations/{conversation_id}/code-changes/sync端点上的用户所有权,可能导致已认证攻击者通过提供其他用户的会话ID写入任意文件更改,从而未经授权修改待处理更改。
CVSS Information
N/A
Vulnerability Type
N/A