CVE-2025-3578
Last modified
CVE-2025-3578 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. A malicious, authenticated user in Aidex, versions prior to 1.7, could list credentials of other users, create or modify existing users in the application, list credentials of users in production or development environments. In addition, it would be possible to cause bugs that would result in the exfiltration of sensitive information, such as details about the software or internal system paths. EPSS estimates a 0.40% chance of exploitation in the next 30 days.
Description
A malicious, authenticated user in Aidex, versions prior to 1.7, could list credentials of other users, create or modify existing users in the application, list credentials of users in production or development environments. In addition, it would be possible to cause bugs that would result in the exfiltration of sensitive information, such as details about the software or internal system paths. These actions could be carried out through the misuse of LLM Prompt (chatbot) technology, via the /api/<string-chat>/message endpoint, by manipulating the contents of the ‘content’ parameter.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-3578?
How severe is CVE-2025-3578?
How do I fix CVE-2025-3578?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-3572SmartRobot from INTUMIT has a Server-Side Request Forgery vu…7.5
- CVE-2025-3573Versions of the package jquery-validation before 1.20.0 are …6.1
- CVE-2025-3574Insecure Direct Object Reference vulnerability in Deporsite …8.7
- CVE-2025-3575Insecure Direct Object Reference vulnerability in Deporsite …8.7
- CVE-2025-3576A vulnerability in the MIT Kerberos implementation allows GS…5.9
- CVE-2025-3577**UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability…4.9
- CVE-2025-3579In versions prior to Aidex 1.7, an authenticated malicious u…9.3
- CVE-2025-3580An access control vulnerability was discovered in Grafana OS…5.5
- CVE-2025-3581The Newsletter WordPress plugin before 8.8.5 does not valid…4.8
- CVE-2025-3582The Newsletter WordPress plugin before 8.85 does not saniti…4.8
- CVE-2025-3583The Newsletter WordPress plugin before 8.7.1 does not sanit…4.8
- CVE-2025-3584The Newsletter WordPress plugin before 8.8.2 does not sanit…4.8
Are you affected by CVE-2025-3578?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
