CVE-2025-70829

An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection string.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:running-elephant:datart:1.0.0:rc3:*:*:*:*:*:*

History

23 Feb 2026, 13:17

Type Values Removed Values Added
First Time Running-elephant
Running-elephant datart
CPE cpe:2.3:a:running-elephant:datart:1.0.0:rc3:*:*:*:*:*:*
References () https://github.com/running-elephant/datart - () https://github.com/running-elephant/datart - Product
References () https://github.com/xiaoxiaoranxxx/CVE-2025-70829 - () https://github.com/xiaoxiaoranxxx/CVE-2025-70829 - Exploit, Third Party Advisory

18 Feb 2026, 17:52

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de exposición de información en Datart v1.0.0-rc.3 permite a atacantes autenticados acceder a datos sensibles a través de una cadena de conexión JDBC H2 personalizada.

17 Feb 2026, 16:20

Type Values Removed Values Added
CWE CWE-200
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.7

17 Feb 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-17 15:16

Updated : 2026-02-23 13:17


NVD link : CVE-2025-70829

Mitre link : CVE-2025-70829

CVE.ORG link : CVE-2025-70829


JSON object : View

Products Affected

running-elephant

  • datart
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor