The application does not verify whether the attacker is the creator of the file, allowing the attacker to directly call the GET /api/chat/file/{file_id} interface to view any user's file.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view