CVE-2025-63664
Unauthorized Message History Access
01Record
| Identifier | CVE-2025-63664 |
|---|---|
| Project | GT Edge AI Platform |
| Component | /api/v1/conversations/*/messages |
| CWE | CWE-284 |
| CVSS | 7.5 |
| Disclosed | 2025-12-22 |
| Writeup | Link |
02Detail
Description: Incorrect access control in the /api/v1/conversations/*/messages API endpoint allows attackers with knowledge of a user ID to read private message history between users and AI agents.
Impact: Information Disclosure, Privilege Escalation
Discovered by Peyton Kennedy (p80n), Richard Medlin.