CVE-2026-82280: Quivrhq Quivr

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite system prompts affecting all brain users.

Affected products

  • Quivrhq Quivr: up to and including 0.0.322

Published 2026-08-28. Last modified 2026-09-23.