Danswer Improper Access Control Vulnerability Allowing Unauthorized Chat Management

Vulnerability

An improper access control vulnerability has been identified in Danswer version 0.3.94. This issue allows the first user created in the system to view, modify, and delete chats created by an Admin. Such access can result in unauthorized exposure of sensitive information, disruption of data integrity, and potential violations of compliance regulations.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, manipulation or deletion of data, and potential compliance violations.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.