6.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X
Description
A vulnerability was identified in coze-studio up to 0.2.4. The impacted element is an unknown function of the file backend/domain/plugin/encrypt/aes.go. The manipulation of the argument AuthSecretKey/StateSecretKey/OAuthTokenSecretKey leads to use of hard-coded cryptographic key
. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is regarded as difficult. To fix this issue, it is recommended to deploy a patch. The vendor replied to the GitHub issue (translated from simplified Chinese): "For scenarios requiring encryption, we will implement user-defined key management through configuration and optimize the use of encryption tools, such as random salt."
. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is regarded as difficult. To fix this issue, it is recommended to deploy a patch. The vendor replied to the GitHub issue (translated from simplified Chinese): "For scenarios requiring encryption, we will implement user-defined key management through configuration and optimize the use of encryption tools, such as random salt."
Basic Information
ID
CVE-2025-9604
Source
VulDB
Published
Aug 29, 2025 at 01:32
Affected Product
Vendor
n/a
Product
coze-studio
Version
0.2.0
Affected Versions
n/a coze-studio 0.2.0
n/a coze-studio 0.2.1
n/a coze-studio 0.2.2
n/a coze-studio 0.2.3
n/a coze-studio 0.2.4
n/a coze-studio 0.2.1
n/a coze-studio 0.2.2
n/a coze-studio 0.2.3
n/a coze-studio 0.2.4