CVE-2024-39314
toy-blog is a headless content management system implementation. Starting in version 0.4.3 and prior to version 0.5.0, the administrative password was leaked through the command line parameter. The problem was patched in version 0.5.0. As a workaround, pass `--read-bearer-token-from-stdin` to the launch arguments and feed the token from the standard input in version 0.4.14 or later. Earlier versions do not have this workaround.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.7
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.19%
- CWE
- CWE-214, CWE-200
- Published
- 2024-07-01
- Last modified
- 2026-03-13
Affected products
- KisaragiEffective toy-blog
Weakness type
Related vulnerabilities
- CVE-2026-81684 — openssl_encrypt before 1.4.9 Information Disclosure via Command Line
- CVE-2026-80158 — Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_log on the bind_pw parameter, disclosing the ipa bind password in logs and process listings
- CVE-2026-65088 — NVIDIA NemoClaw contains a vulnerability where an attacker could cause...
- CVE-2026-76054 — Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17...
- CVE-2026-74873 — openssl_encrypt before 1.4.0 Password Exposure via CLI Argument
- CVE-2026-18915 — Exposure of OTP Secret Through Process Command-Line Arguments in TÜBİTAK BİLGEM's eta-otp-lock
- CVE-2026-12139 — Tanium addressed an information disclosure vulnerability in Connect.
- CVE-2026-9494 — ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line