PT-2025-4774 · Unknown · Next-Forge

Lukem121

·

Published

2025-01-13

·

Updated

2025-01-13

·

CVE-2025-23027

CVSS v4.0

6.3

Medium

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions next-forge (affected versions not specified)
Description The issue concerns a Next.js project boilerplate for modern web applications. A BASEHUB TOKEN is committed in the apps/web/.env.example file. Users are advised to avoid using this token and remove any access it may have in their systems.
Recommendations To resolve the issue, users should remove the BASEHUB TOKEN from their systems and avoid using it. As a mitigation measure, consider restricting access to the apps/web/.env.example file to minimize the risk of exploitation. Avoid using the BASEHUB TOKEN in your applications until the issue is resolved.

Exploit

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-23027
GHSA-WPPX-QMQH-9H33

Affected Products

Next-Forge