CVE-2026-108110: Himovo Movo

Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.

MOVO through 0.2.3 contains an authorization bypass vulnerability in the chat-api document endpoints that allows authenticated users to access other users' stored objects by supplying arbitrary object paths. Attackers who know a target's object path can send it to /api/documents/fetch or /api/documents/save-blueprint to read private documents and overwrite presentation blueprints.

Affected products

  • Himovo Movo: from 0.1.0, up to and including 0.2.3

Published 2026-10-09. Last modified 2026-10-09.