PT-2025-35169 · Unknown · Coze-Studio
Kexinoh
·
Published
2025-08-29
·
Updated
2025-08-29
·
Kexinoh
·
Published
2025-08-29
·
Updated
2025-08-29
·
3.7
Low
| Base vector | Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
backend/domain/plugin/encrypt/aes.go file. Manipulation of the AuthSecretKey, StateSecretKey, and OAuthTokenSecretKey arguments can trigger this issue. The attack can be initiated remotely and is considered difficult to exploit.Fix