Back to overview

CVE-2025-54428

CRITICAL
9.8
CVSS 3.1
Description
RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessible language. In versions below 1.0.1, a valid MongoDB Atlas URI with embedded username and password was accidentally committed to the public repository. This could allow unauthorized access to production or staging databases, potentially leading to data exfiltration, modification, or deletion. This is fixed in version 1.0.1. Workarounds include: immediately rotating credentials for the exposed database user, using a secret manager (like Vault, Doppler, AWS Secrets Manager, etc.) instead of storing secrets directly in code, or auditing recent access logs for suspicious activity.

Metadata

CVE ID
CVE-2025-54428
State
PUBLISHED
Assigner
GitHub_M
Reserved
2025-07-21 23:18 UTC
Published
2025-07-28 20:28 UTC
Last updated
2025-07-28 20:36 UTC
Primary CWE
CWE-522
CWE-522: Insufficiently Protected Credentials
Vendor / Product
musombi123 / RevelaCode-Backend
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
musombi123 RevelaCode-Backend < 1.0.1
Weakness (CWE)
CWESourceDescription
CWE-522 cna CWE-522: Insufficiently Protected Credentials
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References (2)
Back to overview