CVE-2026-3693 | Shy2593666979 AgentChat up to 2.3.0 User Endpoint user.py get_user_info/update_user_info user_id resource injection
A vulnerability has been found in Shy2593666979 AgentChat up to 2.3.0 and classified as critical. This issue affects the function get_user_info/update_user_info of the file /src/backend/agentchat/api/v1/user.py of the component User Endpoint. This manipulation of the argument user_id causes improper control of resource identifiers.
The identification of this vulnerability is CVE-2026-3693. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.