CVE-2025-2129 is a medium-severity vulnerability affecting Mage AI version 0.9.75, categorized as an insecure default initialization of resources (CWE-1188). This remotely exploitable flaw has a CVSS score of 5.6, indicating potential for low impact on confidentiality, integrity, and availability. While exploitability is difficult and attack complexity is high, public exploit code exists, specifically a Nuclei template for "Insecure Default Authentication Setup." Despite public disclosure and researcher follow-ups, Mage AI has declined to address this issue, and there is currently no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | Mage AI | 0.9.75CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.