CVE-2026-108110: Himovo Movo
Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.
MOVO through 0.2.3 contains an authorization bypass vulnerability in the chat-api document endpoints that allows authenticated users to access other users' stored objects by supplying arbitrary object paths. Attackers who know a target's object path can send it to /api/documents/fetch or /api/documents/save-blueprint to read private documents and overwrite presentation blueprints.
Affected products
- Himovo Movo: from 0.1.0, up to and including 0.2.3
Published 2026-10-09. Last modified 2026-10-09.