CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-59714

highCVSS 7.1covered by 1 sourcefirst seen 2026-07-24
Summary Any authenticated user can overwrite the content of a message in a channel they do not belong to (including private and DM channels) by sending a chat completion request with a channel:-prefixed chat_id and a target message_id. The channel: path routes pipeline output through _make_channel_emitter, which writes to the Messages table using the caller-supplied message_id without binding it to the channel. This advisory consolidates two filings of the same flaw: the original single-model form, and a multimodel message_ids variant that survives the partial fix shipped in v0.9.6 (see "Fix status" below). Details (as introduced in v0.9.5) When a user submits a chat completion request with a chat_id starting with channel:, three authorization gaps combined in v0.9.5: 1. Ownership check skipped (main.py): the channel: prefix caused the entire ownership/membership verification block to be skipped, with no channel membership/write check replacing it. if not chat_id.startswith('local:') and not chat_id.startswith('channel:'): # temporary/channel chats are not stored if is_new_chat: ... else: if not await Chats.is_chat_owner(chat_id, user.id) and user.role != 'admin': raise HTTPException(...) 2. Message ID from user input: id (and each value of the multimodel message_ids map) comes directly from the request body and is passed as message_id to the channel emitter. 3. Unchecked database write (socket/main.py _make_channel_emitter): async def _make_channel_emitter(request_info): channel_id = request_info['chat_id'].removeprefix('channel:') message_id = request_info['message_id'] # user-supplied ... await Messages.update_message_by_id(message_id, update_form) # no channel/user authz Messages.update_message_by_id performs a direct primary-key update with no channel_id/user_id validation. Fix (shipped in v0.10.0) v0.9.6 added a channel gate to the channel: branch (PR #24725) that closed the single-model path, but it validated only the first entry of the multimodel

⚡ Watch CVE-2026-59714

Get an email if CVE-2026-59714 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-59714

CVE.org record

Embed the live status

CVE-2026-59714 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-59714 status](https://www.csirts.com/badge/CVE-2026-59714)](https://www.csirts.com/cve/CVE-2026-59714)