Security Advisory

CVE-2026-85669

6.5
MEDIUM

Vulnerability Description

potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpoint. Authenticated attackers can write arbitrary file changes into other users' conversations by supplying their conversation IDs, allowing unauthorized modification of pending changes.
Published Date September 4, 2026
Official Source NIST NVD Advisory