PT-2025-18320 · Base-X · Base-X

Published

2025-04-30

·

Updated

2025-05-02

·

CVE-2025-27611

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions base-x versions prior to 3.0.11 base-x version 4.0.0 base-x version 5.0.0
Description The issue allows attackers to potentially deceive users into sending funds to an unintended address. This is achieved through a problem in the base-x encoder and decoder, which utilizes leading zero compression similar to Bitcoin.
Recommendations For versions prior to 3.0.11, update to version 3.0.11 or later. For version 4.0.0, update to version 4.0.1 or later. For version 5.0.0, update to version 5.0.1 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-27611
GHSA-XQ7P-G2VC-G82P
RHSA-2025:10452
RHSA-2025:10453

Affected Products

Base-X