headroom-ai is vulnerable to Authorization Bypass
91
Critical Risk
The LLM proxy derives the memory owner from the client-supplied x-headroom-user-id header in the OpenAI chat and websocket handlers without binding that value to the authenticated caller. An attacker can set another user's identifier and read or write that user's stored LLM memory. The fix resolves memory identity through resolve_memory_identity, which honors the header only for loopback or allowlisted callers and otherwise binds identity to the proxy-token fingerprint or the operating system user.
You are affected if you are using a version that falls within the vulnerable range and expose the Headroom proxy beyond trusted local clients.
headroom-ai is vulnerable to Authorization Bypass in versions 0.3.0 - 0.36.0.
Upgrade the headroom-ai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant