CVE-2025-57806

MEDIUM

Local Deep Research <0.6.7 - Info Disclosure

Title source: llm
STIX 2.1

Description

Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, including API keys, in a local SQLite database without encryption. This behavior was not clearly documented outside of the database architecture page. Users were not given the ability to configure the database location, allowing anyone with access to the container or host filesystem to retrieve sensitive data in plaintext by accessing the .db file. This is fixed in version 1.0.0.

Scores

CVSS v4 6.9
EPSS 0.0001
EPSS Percentile 0.8%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-312 CWE-522
Status published
Products (1)
LearningCircuit/local-deep-research >= 0.2.0, < 1.0.0
Published Sep 03, 2025
Tracked Since Feb 18, 2026