HIGH 7.1 NVD
CVE-2026-85669
potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpoint. Authenticated attackers can write a
potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpoint. Authenticated attackers can write arbitrary file changes into other users' conversations by supplying their conversation IDs, allowing unauthorized modification of pending changes.
References
- https://github.com/potpie-ai/potpie
- https://github.com/potpie-ai/potpie/blob/v2.0.0/legacy/app/modules/conversations/conversat
- https://github.com/potpie-ai/potpie/issues/870
- https://www.vulncheck.com/advisories/potpie-through-2.0.0-missing-ownership-check-via-code
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-09-04 via NVD.
vulnfeed aggregates 8217 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.