← All research

CVE-2025-63663

Unauthorized File Access via IDOR

01Record

IdentifierCVE-2025-63663
ProjectGT Edge AI Platform
Component/api/v1/conversations/*/files
CWECWE-284
CVSS7.5
Disclosed2025-12-22
WriteupLink

02Detail

Description: Incorrect access control in the /api/v1/conversations/*/files API endpoint allows attackers with knowledge of a user ID to access files uploaded by other users.

Impact: Information Disclosure

Discovered by Peyton Kennedy (p80n), Richard Medlin.