Security Advisory
CVE-2025-57266
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthenticated attackers to gain sensitive information such as API Keys via the /api/assistant/list endpoint.