EmbedAI Improper Access Control Vulnerability Allowing Message Injection in Chats
Vulnerability
A vulnerability allowing improper access control has been identified in EmbedAI versions through 2.1. This issue enables an authenticated attacker to inject messages into other users' chats by manipulating the 'chat_id' parameter in the POST request to the '/embedai/chats/send_message' endpoint.
Impact
Exploitation of this vulnerability allows for improper access control, enabling authenticated attackers to inject messages into the chats of other users.
Remediation
Users can upgrade to EmbedAI version 2.1 or later to address this vulnerability.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
5.2remediation
7.7relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
