Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-63664. PoCs published by RichardMedlin.
AI-analyzed exploit summary This repository contains a technical writeup describing an unauthorized message history access vulnerability (CVE-2025-63664) in an unspecified API endpoint. The issue involves incorrect access control, allowing attackers to read private message history between users and AI agents.
Description
Incorrect access control in the /api/v1/conversations/*/messages API of GT Edge AI Platform before v2.0.10-dev allows unauthorized attackers to access other users' message history with AI agents.
Exploits (1)
This repository contains a technical writeup describing an unauthorized message history access vulnerability (CVE-2025-63664) in an unspecified API endpoint. The issue involves incorrect access control, allowing attackers to read private message history between users and AI agents.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N