Ai2 Playground Web Service Insecure Direct Object Reference Vulnerability

Vulnerability

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Ai2 Playground web service's chat feature, through June 3, 2025. This vulnerability enables attackers to access sensitive information by enumerating thread keys in the URL, thereby gaining unauthorized access to other users' conversation histories. The chat histories are stored on the server without proper ownership distinction, allowing for brute-force access to private conversations.

Impact

Exploitation of this vulnerability allows for unauthorized access to other users' chat histories, including private conversations that have not been publicly shared.

Reproduction

To reproduce this vulnerability, access the Ai2 Playground web service and initiate a chat with the LLM. Conversation histories are stored on the server and can be accessed by brute-forcing the message IDs, which follow a predictable format. The IDs can be manipulated in the URL to retrieve other users' conversation threads.

Added: Jul 22, 2025, 3:21 PM
Updated: Jul 22, 2025, 4:40 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.6
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.