Hardcoded API Key in Project AI Platform Poses Security Risk
CVE-2025-48491

2.7LOW

Key Information:

Vendor

Aryan6673

Vendor
CVE Published:
30 May 2025

What is CVE-2025-48491?

The Project AI platform developed by Aryan Technologies contained a critical security vulnerability due to a hardcoded API key present in its source code before the pre-beta version. This flaw could potentially allow unauthorized access to sensitive functionalities or data. The issue has since been resolved in the latest pre-beta version, ensuring enhanced security for users.

Affected Version(s)

project-ai < pre-beta

References

CVSS V4

Score:
2.7
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48491 : Hardcoded API Key in Project AI Platform Poses Security Risk