CVE-2026-57205

Source
https://cve.org/CVERecord?id=CVE-2026-57205
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57205.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-57205
Aliases
  • GHSA-x2jq-2m5m-65m4
Published
2026-07-16T15:12:46.826Z
Modified
2026-07-18T03:47:51.235009563Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
SimpleChat: Authenticated users can access other users' profile metadata through user IDOR endpoints
Details

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoints in application/singleapp/routebackendusers.py accepted a caller-supplied userid and read the matching Cosmos DB user-settings document without object-level authorization, allowing a low-privilege authenticated user to retrieve another user's email address, display name, and profile image. This issue is fixed in version 0.241.203.

Database specific
{
    "cwe_ids": [
        "CWE-200",
        "CWE-639",
        "CWE-862"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57205.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "0.241.203"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/microsoft/simplechat

Affected ranges

Type
GIT
Repo
https://github.com/microsoft/simplechat
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

0.*
0.190.1
0.190.3
0.202.37
0.202.41
v0.*
v0.179.group_documents.13
v0.185.0
v0.185.1
v0.191.0
v0.196.9
v0.199.3
v0.201.5
v0.202.21
v0.203.15
v0.203.16
v0.212.078
v0.212.079
v0.212.091
v0.213.001
v0.213.003
v0.214.001
v0.215.34
v0.215.35
v0.215.36
v0.215.37
v0.215.38
v0.229.001
v0.229.002
v0.229.014
v0.229.058
v0.229.060
v0.229.061
v0.229.062
v0.229.063
v0.229.098
v0.235.001
v0.235.003
v0.235.012
v0.235.025
v0.237.001
v0.237.003
v0.237.004
v0.237.005
v0.237.006
v0.237.007
v0.237.009
v0.237.011
v0.239.001
v0.239.002
v0.241.001
v0.241.002
v0.241.006
v0.241.007

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57205.json"