CVE Explorer
CVE-2026-32097
PingPong is a platform for using large language models (LLMs) for teaching and learning. Prior to 7.27.2, an authenticated user may be able to retrieve or delete files outside the intended authorization scope. This issue could result in retrieval or deletion of private files, including user-uploaded files and model-generated output files. Exploitation required authentication and permission to view at least one thread for retrieval, and authentication and permission to participate in at least one
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"pingpong","vendor":"comppolicylab","versions":[{"status":"affected","version":"< 7.27.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ca6ec2f49d346848c6b3672dbc3ff99a63825ae32f123bb09230f682879582a6 · sha256:20f06794a8b960d0… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.6,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ca6ec2f49d346848c6b3672dbc3ff99a63825ae32f123bb09230f682879582a6 · sha256:20f06794a8b960d0… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-639","description":"CWE-639: Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ca6ec2f49d346848c6b3672dbc3ff99a63825ae32f123bb09230f682879582a6 · sha256:20f06794a8b960d0… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/comppolicylab/pingpong/security/advisories/GHSA-4wwr-5wq7-mgm4","tags":["x_refsource_CONFIRM"],"url":"https://github.com/comppolicylab/pingpong/security/advisories/GHSA-4wwr-5wq7-mgm4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ca6ec2f49d346848c6b3672dbc3ff99a63825ae32f123bb09230f682879582a6 · sha256:20f06794a8b960d0… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.