PT-2025-35648 · Unknown · Local-Deep-Research

I-D-Lytvynenko

·

Published

2025-09-03

·

Updated

2025-09-03

·

CVE-2025-57806

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Local Deep Research versions 0.2.0 through 0.6.7
Description Local Deep Research stores confidential information, including API keys, in a local SQLite database without encryption. This behavior was not clearly documented. Users were not given the ability to configure the database location, allowing anyone with access to the container or host filesystem to retrieve sensitive data in plaintext by accessing the .db file.
Recommendations Update to version 1.0.0.

Exploit

Fix

Insufficiently Protected Credentials

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-57806
GHSA-4H8C-QRCQ-CV5C

Affected Products

Local-Deep-Research