PT-2025-16307 · Aidex · Aidex

Published

2025-04-15

·

Updated

2025-04-16

·

CVE-2025-3578

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Aidex versions prior to 1.7
Description A malicious, authenticated user could list credentials of other users, create or modify existing users in the application, list credentials of users in production or development environments, and cause bugs that would result in the exfiltration of sensitive information. These actions could be carried out through the misuse of LLM Prompt (chatbot) technology, via the "/api//message" endpoint, by manipulating the contents of the content parameter.
Recommendations For Aidex versions prior to 1.7, as a temporary workaround, consider restricting access to the "/api//message" endpoint until a patch is available. Additionally, avoid using the content parameter in the affected API endpoint until the issue is resolved. Update to version 1.7 or later to fully resolve the issue.

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-3578

Affected Products

Aidex