EmbedAI Improper Access Control Vulnerability Allowing Message Injection in Chats

Vulnerability

A vulnerability allowing improper access control has been identified in EmbedAI versions through 2.1. This issue enables an authenticated attacker to inject messages into other users' chats by manipulating the 'chat_id' parameter in the POST request to the '/embedai/chats/send_message' endpoint.

Impact

Exploitation of this vulnerability allows for improper access control, enabling authenticated attackers to inject messages into the chats of other users.

Remediation

Users can upgrade to EmbedAI version 2.1 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.