CVE-2026-3693 is a high-severity vulnerability affecting Shy2593666979 AgentChat up to version 2.3.0, specifically within the user endpoint functions get_user_info and update_user_info. This flaw, categorized as improper control of resource identifiers (CWE-99), allows remote attackers to manipulate the user_id argument. The CVSS score of 7.3 (HIGH) indicates a low attack complexity and no user interaction required, with potential for low impact on confidentiality, integrity, and availability. While an exploit has been published, there is no evidence of active exploitation, and it lacks presence in common exploit frameworks or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Shy2593666979 | AgentChat | 2.0, 2.1, 2.2, 2.3.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.