PT-2025-49415 · Nutshell · Nutshell

Published

2025-12-07

·

Updated

2026-05-29

·

CVE-2025-65548

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions nutshell (cashubtc/nuts) versions prior to 0.18.0
Description NUT-14 allows cashu tokens to be created using a preimage hash. In affected versions, the software fails to validate the size of the preimage when a token is spent. Because the mint stores this preimage, an attacker can exploit this lack of validation to fill the mint's database and disk with arbitrary data.
Recommendations Update to version 0.18.0 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-65548
PYSEC-2025-89

Affected Products

Nutshell