PT-2026-23894 · Shy2593666979 · Agentchat
Vuldb
·
Published
2026-03-08
·
Updated
2026-03-13
·
CVE-2026-3693
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Shy2593666979 AgentChat versions prior to 2.3.1
Description
A flaw exists in Shy2593666979 AgentChat related to improper control of resource identifiers. The issue resides within the
get user info/update user info function located in the /src/backend/agentchat/api/v1/user.py file of the User Endpoint component. Manipulation of the user id argument can trigger the issue, and the attack can be initiated remotely. The exploit for this issue has been published.Recommendations
Update Shy2593666979 AgentChat to version 2.3.1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Agentchat