CVE-2025-65109
Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and Minder Go versions from 0.0.72 to 0.0.83, Minder users may fetch content in the context of the Minder server, which may include URLs which the user would not normally have access to. This issue has been patched in Minder Helm version 0.20250203.3849+ref.fdc94f0 and Minder Go version 0.0.84.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L
- EPSS probability
- 0.28%
- CWE
- CWE-830
- Published
- 2025-11-21
- Last modified
- 2026-03-12
Affected products
- mindersec minder
- mindersec minder
Weakness type
Related vulnerabilities
- CVE-2025-64496 — Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
- CVE-2025-46652 — In IZArc through 4.5, there is a Mark-of-the-Web Bypass Vulnerability. When a user performs an...
- CVE-2025-43703 — An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in...
- CVE-2025-33028 — In WinZip through 29.0, there is a Mark-of-the-Web Bypass Vulnerability because of an incomplete...
- CVE-2025-33027 — In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This...
- CVE-2025-33026 — In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability...
- CVE-2024-35180 — OMERO.web JSONP callback vulnerability
- CVE-2023-2588