We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verify whether the attacker is the creator of the file, allowing the attacker to directly call the GET /api/chat/file/{file_id} interface to view any user's file.
Reserved 2024-10-07 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_aiCWE-284 Improper Access Control
huntr.com/bounties/8f683ff6-3a99-41c6-b763-a8f7b73bd146
Support options