Insecure Direct Object Reference Vulnerability in BOLD Workplanner by BOLD
CVE-2025-41099
Key Information:
- Status
- Vendor
- CVE Published:
- 30 September 2025
What is CVE-2025-41099?
The BOLD Workplanner has been identified with an Insecure Direct Object Reference vulnerability due to insufficient validation of user inputs. This flaw allows authenticated users to exploit unauthorized internal identifiers, potentially exposing a detailed list of permissions they should not access. To mitigate this risk, it is crucial for users to upgrade to version 2.5.25 or above, where this issue has been addressed. Regular audits and updates can significantly enhance security and protect sensitive information from unauthorized access.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BOLD Workplanner 2.5.24
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
