PT-2025-48098 · Coreboot · Coreboot

Published

2025-11-25

·

Updated

2025-11-26

·

CVE-2025-65957

CVSS v4.0

8.8

High

VectorAV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:L/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions Core Bot versions prior to commit dffe050
Description Core Bot, an open source discord bot for maple hospital servers, experienced an issue where API keys (SUPABASE API KEY, TOKEN) loaded from environment variables could be inadvertently leaked through configuration summaries in error handling, summaries, and webhooks. Sensitive data was potentially exposed in summary embeds and logs due to a failure to redact it.
Recommendations Update to commit dffe050 or later to resolve the issue.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65957
GHSA-42J6-X28V-38R8

Affected Products

Coreboot