CVE-2025-0741

CVSS 3.1 Score 5.8 of 10 (medium)

Details

Published Jan 30, 2025
Updated: Feb 18, 2025
CWE ID 284

Summary

CVE-2025-0741 is an access control vulnerability affecting EmbedAI versions 2.1 and below. This issue allows authenticated attackers to manipulate chat messages by altering the "chat_id" parameter in POST requests to the "/embedai/chats/send_message" endpoint. Consequently, attackers can write messages into other users' chats, posing a significant security risk. EmbedAI users are advised to update their software to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share