CVE 9.8 CRITICAL

RevelaCode exposes Sensitive MongoDB Atlas URI in .env (potential credential leak)_CVE-2025-54428

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessible language. In versions below 1.0.1, a valid MongoDB Atlas URI with embedded username and password was accidentally committed to the public repository. This could allow unauthorized access to production or staging databases, potentially leading to data exfiltration, modification, or deletion. This is fixed in version 1.0.1. Workarounds include: immediately rotating credentials for the exposed database user, using a secret manager (like Vault, Doppler, AWS Secrets Manager, etc.) instead of storing secrets directly in code, or auditing recent access logs for suspicious activity.

Basic Information

ID CVE-2025-54428
Source GitHub_M
Published Jul 28, 2025 at 20:28
Modified Jul 28, 2025 at 20:36

Affected Product

Vendor musombi123
Product RevelaCode-Backend
Version < 1.0.1
Affected Versions musombi123 RevelaCode-Backend < 1.0.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.