CVE-2025-46332
Last modified
CVE-2025-46332 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Flags SDK is an open-source feature flags toolkit for Next.js and SvelteKit. Impacted versions include flags from 3.2.0 and prior and @vercel/flags from 3.1.1 and prior as certain circumstances allows a bad actor with detailed knowledge of the vulnerability to list all flags returned by the flags discovery endpoint (.well-known/vercel/flags). EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Flags SDK is an open-source feature flags toolkit for Next.js and SvelteKit. Impacted versions include flags from 3.2.0 and prior and @vercel/flags from 3.1.1 and prior as certain circumstances allows a bad actor with detailed knowledge of the vulnerability to list all flags returned by the flags discovery endpoint (.well-known/vercel/flags). This vulnerability allows for information disclosure, where a bad actor could gain access to a list of all feature flags exposed through the flags discovery endpoint, including the flag names, flag descriptions, available options and their labels (e.g. true, false), and default flag values. This issue has been patched in flags@4.0.0, users of flags and @vercel/flags should also migrate to flags@4.0.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-46332?
How severe is CVE-2025-46332?
How do I fix CVE-2025-46332?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-46327gosnowflake is the Snowflake Golang driver. Versions startin…7
- CVE-2025-46328snowflake-connector-nodejs is a NodeJS driver for Snowflake.…7
- CVE-2025-46329libsnowflakeclient is the Snowflake Connector for C/C++. Ver…3.3
- CVE-2025-4633Default credentials were present in the web portal for Airpo…6.5
- CVE-2025-46330libsnowflakeclient is the Snowflake Connector for C/C++. Ver…3.3
- CVE-2025-46331OpenFGA is a high-performance and flexible authorization/per…9.8
- CVE-2025-46333z2d is a pure Zig 2D graphics library. Versions of z2d after…7.3
- CVE-2025-46334Git GUI allows you to use the Git source control management …8.6
- CVE-2025-46335Mobile Security Framework (MobSF) is a security research pla…5.4
- CVE-2025-46336Rack::Session is a session management implementation for Rac…4.2
- CVE-2025-46337ADOdb is a PHP database class library that provides abstract…10
- CVE-2025-46338Audiobookshelf is a self-hosted audiobook and podcast server…6.1
Are you affected by CVE-2025-46332?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
