CVE 9.6 CRITICAL

CVE-2025-63691_CVE-2025-63691

9.6 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Description

In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the token query interface (/api/admin/sys-token/page) has an improper permission verification issue, which leads to information leakage. This interface can be called by any user who has completed login authentication, and it returns the plaintext authentication Tokens of all users currently logged in to the system. As a result, ordinary users can obtain the administrator's authentication Token through this interface, thereby forging an administrator account, gaining the system's management permissions, and taking over the system.

AI Analysis

Information disclosure vulnerability due to improper permission verification in the token query interface

Basic Information

ID CVE-2025-63691
Source mitre
Published Nov 7, 2025 at 00:00
Modified Nov 7, 2025 at 18:49

Affected Product

Vendor Pig Mesh
Product Pig
Version 3.8.2 and below
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 9.6 / 10
AI Severity Critical
Vendor Pig Mesh
Product Pig
Version 3.8.2 and below

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.