CVE-2025-57266

Publication date

2025-09-29 00:00:00

Family

mitre

State

PUBLISHED

Description

An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthenticated attackers to gain sensitive information such as API Keys via the /api/assistant/list endpoint.