CVE-2025-57266
CRITICALThriveX Blogging Framework <3.1.3 - Info Disclosure
Title source: llmDescription
An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthenticated attackers to gain sensitive information such as API Keys via the /api/assistant/list endpoint.
References (2)
Core 2
Core References
Issue Tracking
https://github.com/LiuYuYang01/ThriveX-Server/issues/55
Scores
CVSS v3
9.8
EPSS
0.0034
EPSS Percentile
25.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-284
Status
published
Published
Sep 29, 2025
Tracked Since
Feb 18, 2026