PT-2025-39877 · Unknown · Thrivex Blogging Framework

Candy

·

Published

2025-09-29

·

Updated

2025-12-23

·

CVE-2025-57266

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ThriveX Blogging Framework versions 2.5.9 through 3.1.3
Description An issue exists in the AssistantController.java file that allows unauthenticated attackers to obtain sensitive information, such as API Keys. The /api/assistant/list API endpoint is affected. The issue allows gaining access to sensitive information.
Recommendations Update ThriveX Blogging Framework to a version later than 3.1.3.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-57266

Affected Products

Thrivex Blogging Framework