CVE-2026-85669 UNKNOWN

CVE-2026-85669

Published: 2026-09-04

Description

potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpoint. Authenticated attackers can write arbitrary file changes into other users' conversations by supplying their conversation IDs, allowing unauthorized modification of pending changes.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…