potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpoint. Authenticated attackers can write arbitrary file changes into other users' conversations by supplying their conversation IDs, allowing unauthorized modification of pending changes.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-04 15:17
Updated : 2026-09-10 16:18
NVD link : CVE-2026-85669
Mitre link : CVE-2026-85669
CVE.ORG link : CVE-2026-85669
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
