CVE-2025-49009 is a vulnerability in Para, a multitenant backend server, affecting versions prior to 1.50.8. It involves the logging of full request URLs, including Facebook user access tokens in plain text, during failed Facebook profile requests. This medium-severity vulnerability (CVSS 6.2) has a low attack complexity and can lead to sensitive information disclosure if WARN-level logs are accessible. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Erudika | Para | < 1.50.8CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.