CVE-2025-70829

MEDIUM

Datart 1.0.0-rc.3 - Info Disclosure

Title source: llm

Description

An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection string.

Exploits (1)

nomisec WRITEUP 1 stars
by xiaoxiaoranxxx · poc
https://github.com/xiaoxiaoranxxx/CVE-2025-70829

Scores

CVSS v3 5.7
EPSS 0.0005
EPSS Percentile 14.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
running-elephant/datart 1.0.0 rc3
Published Feb 17, 2026
Tracked Since Feb 18, 2026