Security Advisory
CVE-2026-85669
6.5
MEDIUM
Vulnerability Description
potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpoint. Authenticated attackers can write arbitrary file changes into other users' conversations by supplying their conversation IDs, allowing unauthorized modification of pending changes.
Published Date
September 4, 2026
Official Source
NIST NVD Advisory