PT-2025-48410 · Nutzam · Nutzboot

Sh7Err03

·

Published

2025-12-01

·

Updated

2025-12-30

·

CVE-2025-13806

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions nutzam NutzBoot versions up to 2.6.0-SNAPSHOT
Description A security issue exists in nutzam NutzBoot related to improper authorization within the Transaction API. The issue stems from manipulation of the from, to, and wei arguments in an unknown function within the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthModule.java. Remote exploitation is possible, and the exploit has been publicly disclosed.
Recommendations Versions prior to 2.6.0-SNAPSHOT should be used.

Exploit

Fix

Incorrect Authorization

Incorrect Privilege Assignment

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-13806
GHSA-53V5-9752-QQ92

Affected Products

Nutzboot