# CVE-2025-55306

## Summary

- **CVE ID:** CVE-2025-55306
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-522
- **Published:** Aug 19, 2025
- **Last Modified:** Mar 12, 2026

## Description

GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys and authentication tokens may be exposed if environment variables are misconfigured. Unauthorized users could gain access to cloud resources (Google Cloud, Firebase, GitHub, etc.).

## Affected Products

- Mouy-leng — GenX_FX (<= 1.0.0)

## References

- [CNA](https://github.com/Mouy-leng/GenX_FX/security/advisories/GHSA-2xjq-pvwj-mvm6)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.56%
- **EPSS Percentile:** 44.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._