Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object Reference (IDOR), allowing attackers to gain sensitvie information via enumerating thread keys in the URL.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.