CVE-2025-51868
HIGHDippy v2 - Insecure Direct Object Reference via conversation_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-51868. PoCs published by Secsys-FDU.
AI-analyzed exploit summary The repository describes an Insecure Direct Object Reference (IDOR) vulnerability in Dippy's chat component, allowing attackers to access other users' conversation histories by brute-forcing predictable conversation IDs. The README provides a technical overview of the attack vector and its impact.
Description
Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive information via the conversation_id parameter to the conversation_history endpoint.
Exploits (1)
The repository describes an Insecure Direct Object Reference (IDOR) vulnerability in Dippy's chat component, allowing attackers to access other users' conversation histories by brute-forcing predictable conversation IDs. The README provides a technical overview of the attack vector and its impact.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N