CVE-2025-51869

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Insecure Direct Object Reference (IDOR) vulnerability in Liner thru 2025-06-03 allows attackers to gain sensitive information via crafted space_id, thread_id, and message_id parameters to the v1/space/{space_id}/thread/{thread_id}/message/{message_id} endpoint.

Published 2025-07-21. Last modified 2026-06-17.