Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-48491

13
FAUCET Score

CVE-2025-48491 describes a hardcoded API key vulnerability in Project AI, specifically in versions prior to the pre-beta release. This flaw, categorized as CWE-798, could allow unauthorized access to the platform due to the exposed credential. With a CVSS score of 2.7 (LOW), the vulnerability has a network attack vector and low impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
Aryan6673Project-Ai
< pre-betaCNA affected

CVSS Data

CVSS version used by this source: 4.0

2.7LOW

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
UNREPORTED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.48%
Probability of exploitation in next 30 days
EPSS Percentile
38.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0048 is in the 55th percentile among its peer group of 61 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / aryan6673/project-ai/commit/142252c43f1dacb3fed99e3336f5cd863b028bc2
github.com / aryan6673/project-ai/commit/1de910f353eb2a68c980149b906e7495459296ad
github.com / aryan6673/project-ai/commit/54a69c3ccd301d35f3d54f4844d9910e609beb73
github.com / aryan6673/project-ai/commit/7f3b93f9aa9085d5413b4019172b0e56676346d7
github.com / aryan6673/project-ai/commit/8db90e3d9777850741804533ebde5824b4a5795c
github.com / aryan6673/project-ai/commit/99e0e0718edb0e59c5d3c5a69903b87c69fcfe7a
github.com / aryan6673/project-ai/commit/ab67979a46b0e343dc20a95a2b65d3c4994c31e7
github.com / aryan6673/project-ai/commit/c1fb156418d98a1e6c60bb680db57e9558785093
github.com / aryan6673/project-ai/security/advisories/GHSA-8486-vrcp-69rv