CVE 6.3 MEDIUM

coze-studio aes.go hard-coded key_CVE-2025-9604

6.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X

Description

A vulnerability was identified in coze-studio up to 0.2.4. The impacted element is an unknown function of the file backend/domain/plugin/encrypt/aes.go. The manipulation of the argument AuthSecretKey/StateSecretKey/OAuthTokenSecretKey leads to use of hard-coded cryptographic key
. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is regarded as difficult. To fix this issue, it is recommended to deploy a patch. The vendor replied to the GitHub issue (translated from simplified Chinese): "For scenarios requiring encryption, we will implement user-defined key management through configuration and optimize the use of encryption tools, such as random salt."

Basic Information

ID CVE-2025-9604
Source VulDB
Published Aug 29, 2025 at 01:32

Affected Product

Vendor n/a
Product coze-studio
Version 0.2.0
Affected Versions n/a coze-studio 0.2.0
n/a coze-studio 0.2.1
n/a coze-studio 0.2.2
n/a coze-studio 0.2.3
n/a coze-studio 0.2.4

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.