CVE-2025-70829

MEDIUM

Datart 1.0.0-rc.3 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-70829. PoCs published by xiaoxiaoranxxx.

AI-analyzed exploit summary The repository describes an information exposure vulnerability in Datart v1.0.0-rc.3, where authenticated attackers can access sensitive data via a custom H2 JDBC connection string. However, it lacks technical details or exploit code.

Description

An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection string.

Exploits (1)

nomisec WRITEUP 1 stars
by xiaoxiaoranxxx · poc
https://github.com/xiaoxiaoranxxx/CVE-2025-70829

The repository describes an information exposure vulnerability in Datart v1.0.0-rc.3, where authenticated attackers can access sensitive data via a custom H2 JDBC connection string. However, it lacks technical details or exploit code.

Classification
Writeup 60%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Theoretical
Target: Datart v1.0.0-rc.3
Auth required
Prerequisites: Authenticated access to the target system
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 5.7
EPSS 0.0043
EPSS Percentile 34.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
running-elephant/datart 1.0.0 rc3
Published Feb 17, 2026
Tracked Since Feb 18, 2026