CVE-2025-59036 affects Infrahub versions prior to 1.3.9 and 1.4.5, where a flaw in authentication logic allows previously deleted or expired API tokens to remain valid for active user accounts. This medium severity vulnerability (CVSS 5.5) has a network attack vector and low attack complexity, potentially leading to limited confidentiality, integrity, and availability impacts if an attacker gains access to such a token. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Opsmill | Infrahub | < 1.3.9, >= 1.4.0, < 1.4.5CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.