CVE-2026-85669

potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpoint. Authenticated attackers can write arbitrary file changes into other users' conversations by supplying their conversation IDs, allowing unauthorized modification of pending changes.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-04 15:17

Updated : 2026-09-10 16:18


NVD link : CVE-2026-85669

Mitre link : CVE-2026-85669

CVE.ORG link : CVE-2026-85669


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization