PatchSiren

QuivrHQ CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH QuivrHQ CVE published 2026-08-28

CVE-2026-82284

CVE-2026-82284 debrief based on the supplied source corpus. The CVE record was published on 2026-08-28T20:20:19.823Z and has not been modified since then. The vulnerability affects Quivr versions through 0.0.322, specifically in chat endpoints, allowing authenticated attackers to read other users' conversation histories, delete arbitrary chats, and inject fabricated messages. Defenders should assess expos [truncated]

HIGH QuivrHQ CVE published 2026-08-28

CVE-2026-82280

CVE-2026-82280 is a high-severity vulnerability in Quivr, a tool that allows users to create and manage prompts. The vulnerability, which has a CVSS score of 7.1, occurs because Quivr fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. This could potentially allow attackers with read-only access to shared brains to read exposed prompt identifie [truncated]