CVE-2025-66698

HIGH

Semantic machines <5.4.8 - Auth Bypass

Title source: llm

Description

An issue in Semantic machines v5.4.8 allows attackers to bypass authentication via sending a crafted HTTP request to various API endpoints.

Exploits (1)

nomisec WRITEUP
by Perunchess · poc
https://github.com/Perunchess/CVE-2025-66698

Scores

CVSS v3 8.6
EPSS 0.0019
EPSS Percentile 41.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-287
Status published
Products (1)
semantic-machines/veda 5.4.8
Published Jan 13, 2026
Tracked Since Feb 18, 2026