CVE-2025-7080
Last modified
CVE-2025-7080 is a low-severity vulnerability rated 3.7/10 on the CVSS scale. A vulnerability, which was classified as problematic, was found in Done-0 Jank up to 322caebbad10568460364b9667aa62c3080bfc17. Affected is an unknown function of the file internal/utils/jwt_utils.go of the component JWT Token Handler. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
A vulnerability, which was classified as problematic, was found in Done-0 Jank up to 322caebbad10568460364b9667aa62c3080bfc17. Affected is an unknown function of the file internal/utils/jwt_utils.go of the component JWT Token Handler. The manipulation of the argument accessSecret/refreshSecret with the input jank-blog-secret/jank-blog-refresh-secret leads to use of hard-coded password. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-7080?
How severe is CVE-2025-7080?
How do I fix CVE-2025-7080?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-70791Cross Site Scripting vulnerability in the "/admin/order/aban…6.1
- CVE-2025-70792Cross Site Scripting vulnerability in the "/admin/category/c…6.1
- CVE-2025-70795STProcessMonitor 11.11.4.0, part of the Safetica Application…5.5
- CVE-2025-70796An unauthenticated path traversal vulnerability exists in th…7.5
- CVE-2025-70797Cross Site Scripting vulnerability in Limesurvey v.6.15.20+2…6.1
- CVE-2025-70798Tenda i24V3.0si V3.0.0.5 Firmware V3.0.0.5 was discovered to…8.4
- CVE-2025-70802Tenda G1V3.1si V16.01.7.8 Firmware V16.01.7.8 was discovered…8.4
- CVE-2025-7081A vulnerability has been found in Belkin F9K1122 1.00.33 and…8.8
- CVE-2025-70810Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.…8.8
- CVE-2025-70811Cross Site Request Forgery vulnerability in Phpbb phbb3 v.3.…4.3
- CVE-2025-7082A vulnerability was found in Belkin F9K1122 1.00.33 and clas…8.8
- CVE-2025-70821renren-secuity before v5.5.0 is vulnerable to SQL Injection …9.8
Are you affected by CVE-2025-7080?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
