<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:quivr:quivr:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aquivrquivr/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 28 Aug 2026 21:38:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aquivrquivr/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in Quivr Prompt Management</title><link>https://feed.craftedsignal.io/briefs/2026-08-quivr-auth-bypass/</link><pubDate>Fri, 28 Aug 2026 21:38:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-quivr-auth-bypass/</guid><description>An authorization flaw in Quivr versions 0.0.322 and earlier allows authenticated users to modify or overwrite arbitrary prompts via unvalidated API endpoints.</description><content:encoded><![CDATA[<p>Quivr versions up to and including 0.0.322 contain a critical authorization vulnerability (CVE-2026-82280) within its prompt management endpoints. The application fails to perform adequate ownership validation when processing requests to modify prompts. This allows any authenticated user, including those with only read-only access to shared 'brains', to discover valid prompt identifiers and subsequently issue unauthorized requests to overwrite them. By successfully altering these system prompts, an attacker can modify the behavior of the AI model for all users who interact with the affected shared environment. This vulnerability poses a significant risk to the integrity of AI-driven workflows and could be leveraged to perform prompt injection at scale or disrupt service delivery across an entire organizational brain.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation enables an attacker to manipulate AI model responses by overwriting system prompts, potentially affecting all users connected to a compromised shared brain. This can lead to unauthorized information disclosure, the injection of malicious instructions, and a complete loss of control over the AI-generated output for specific tasks within the Quivr platform.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade Quivr to a version beyond 0.0.322 as soon as a patch is available.</li>
<li>Implement restrictive API gateway controls to audit access to prompt-related endpoints until the vulnerability is remediated.</li>
<li>Audit logs for unauthorized POST, PUT, or PATCH requests directed at prompt modification endpoints by accounts with restricted or read-only privileges.</li>
<li>Monitor for anomalous prompt identifier discovery patterns in web server logs originating from low-privilege service accounts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>