← All research

CVE-2025-63664

Unauthorized Message History Access

01Record

IdentifierCVE-2025-63664
ProjectGT Edge AI Platform
Component/api/v1/conversations/*/messages
CWECWE-284
CVSS7.5
Disclosed2025-12-22
WriteupLink

02Detail

Description: Incorrect access control in the /api/v1/conversations/*/messages API endpoint allows attackers with knowledge of a user ID to read private message history between users and AI agents.

Impact: Information Disclosure, Privilege Escalation

Discovered by Peyton Kennedy (p80n), Richard Medlin.