CVE-2025-27611
base-x is a base encoder and decoder of any given alphabet using bitcoin style leading zero compression. Versions 4.0.0, 5.0.0, and all prior to 3.0.11, are vulnerable to attackers potentially deceiving users into sending funds to an unintended address. This issue has been patched in versions 3.0.11, 4.0.1, and 5.0.1.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.43%
- CWE
- CWE-1007
- Published
- 2025-04-30
- Last modified
- 2026-03-13
Affected products
- cryptocoinjs base-x
- cryptocoinjs base-x
- cryptocoinjs base-x
Weakness type
Related vulnerabilities
- CVE-2026-48760 — Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense
- CVE-2026-45064 — Symfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing
- CVE-2025-0996 — Inappropriate implementation in Browser UI in Google Chrome on Android prior to 133.0.6943.98...