← Back to CVE List
Vulnerability Intelligence Report
SimpleChat: Authenticated users can access other users' profile metadata through user IDOR endpoints

CVE-2026-57205

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoints in application/single_app/route_backend_users.py accepted a caller-supplied user_id and read the matching Cosmos DB user-settings document without object-level authorization, allowing a low-privilege authenticated user to retrieve another user's email address, display name, and profile image. This issue is fixed in version 0.241.203.

Information Disclosure No Active Exploit Signals
CVSS Base Score
4.3
MEDIUM
Exploitability:2.9
Impact Score:1.5
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-200 ↗CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CWE-639 ↗CWE-639: Authorization Bypass Through User-Controlled Key
CWE-862 ↗CWE-862: Missing Authorization

Affected Products & Versions

Vendor Product Affected Versions
microsoft simplechat < 0.241.203 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Vulnerability Class
Information Disclosure

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-06-24T02:00:46
Published2026-07-16T15:12:46
Last Updated2026-07-16T15:25:26

LINK COPIED TO CLIPBOARD