Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-51865. PoCs published by Secsys-FDU.
AI-analyzed exploit summary The repository describes an Insecure Direct Object Reference (IDOR) vulnerability in Ai2's playground web application, allowing attackers to brute-force conversation message IDs to access other users' chat histories. The attack vector relies on predictable message ID formats (e.g., `msg_A1A1A1A1A1`).
Description
Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to gain sensitvie information via enumerating thread keys in the URL.
Exploits (1)
The repository describes an Insecure Direct Object Reference (IDOR) vulnerability in Ai2's playground web application, allowing attackers to brute-force conversation message IDs to access other users' chat histories. The attack vector relies on predictable message ID formats (e.g., `msg_A1A1A1A1A1`).
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H