Sensitive Data Exposure in CapillaryScope by Capillary io
CVE-2025-40680

6.9MEDIUM

Key Information:

Vendor
CVE Published:
24 July 2025

What is CVE-2025-40680?

In version 2.5.0 of CapillaryScope by Capillary io, sensitive information such as proxy credentials and JWT session tokens are stored without encryption in plaintext within various registry keys on Windows. This security oversight allows any local user with read access to the registry to easily extract and misuse these critical credentials, increasing the risk of unauthorized access and data breaches. It's essential for users to understand the implications of this vulnerability and take necessary steps to secure sensitive data.

Affected Version(s)

CapillaryScope 0 < 2.5.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ismael Melchor Juan
Pedro José Navas Pérez
.