Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85693— Chatbot UI Cross-User Private File Content Disclosure via Retrieval API

Quick assessment

Affected
mckaywrigley chatbot-ui
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Chatbot 界面存在一个授权绕过漏洞,位于检索端点中,允许经过身份验证的攻击者通过提供任意文件 UUID 来访问其他用户的私有文件内容。该端点使用基于服务角色的 Supabase 客户端,该客户端绕过了行级安全策略,且未对文件所有权进行验证,从而允许攻击者通过精心构造的 POST 请求,从受害者的文件中检索出已索引的内容块。

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts

Affected Version Matrix 1

VendorProduct Version RangeStatus
mckaywrigley chatbot-ui ≤ 81328b61d2a4ab597a7a057be70e785cf756d9f8 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85693

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Chatbot UI Cross-User Private File Content Disclosure via Retrieval API
Source: CVE Program / CVE List V5
Vulnerability Description
Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other users by supplying arbitrary file UUIDs. The endpoint uses a service-role Supabase client that bypasses row-level security and fails to validate file ownership, enabling attackers to retrieve indexed content chunks from victim files through crafted POST requests.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
mckaywrigley chatbot-ui 0 ~ 81328b61d2a4ab597a7a057be70e785cf756d9f8 -

II. Public POCs for CVE-2026-85693

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85693

登录查看更多情报信息。

Patches & Fixes for CVE-2026-85693 (1)

Vendor Advisories for CVE-2026-85693 (1)

Other References for CVE-2026-85693 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85693

No comments yet


Leave a comment