Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31634 | An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthenticated attackers to gain sensitive information such as API Keys via the /api/assistant/list endpoint. |
Tue, 30 Sep 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thrivex
Thrivex blog |
|
| Vendors & Products |
Thrivex
Thrivex blog |
Mon, 29 Sep 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Mon, 29 Sep 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthenticated attackers to gain sensitive information such as API Keys via the /api/assistant/list endpoint. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-29T20:39:21.912Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-57266
Updated: 2025-09-29T20:39:09.324Z
Status : Deferred
Published: 2025-09-29T21:15:38.180
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-57266
No data.
OpenCVE Enrichment
Updated: 2025-09-30T08:48:24Z
EUVD