Sensitive Data Exposure in CapillaryScope by Capillary io
CVE-2025-40680
6.9MEDIUM
What is CVE-2025-40680?
In version 2.5.0 of CapillaryScope by Capillary io, sensitive information such as proxy credentials and JWT session tokens are stored without encryption in plaintext within various registry keys on Windows. This security oversight allows any local user with read access to the registry to easily extract and misuse these critical credentials, increasing the risk of unauthorized access and data breaches. It's essential for users to understand the implications of this vulnerability and take necessary steps to secure sensitive data.
Affected Version(s)
CapillaryScope 0 < 2.5.0