CVE-2025-25975: Infoleak
Published Mar 12, 2025
·Updated
An issue in parse-git-config v.3.0.0 allows an attacker to obtain sensitive information via the expandKeys function
Affected Software
3 affected components
parse-git-config parse-git-config
npm/parse-git-config<=3.0.0
Jonschlinkert Parse-git-config=3.0.0
Event History
Mar 12, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-25975?
CVE-2025-25975 has a medium severity rating due to its potential to expose sensitive information.
2
How do I fix CVE-2025-25975?
To fix CVE-2025-25975, update the parse-git-config package to version 3.0.1 or later.
3
What versions of parse-git-config are affected by CVE-2025-25975?
CVE-2025-25975 affects parse-git-config version 3.0.0 and below.
4
What kind of information can be exposed by CVE-2025-25975?
CVE-2025-25975 allows attackers to potentially access sensitive information through the expandKeys function.
5
Is there a public exploit for CVE-2025-25975?
As of now, there are no publicly available exploits specifically targeting CVE-2025-25975.