Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.
References
| Link | Resource |
|---|---|
| https://gist.github.com/old6ma/9c4d2ba32cd8f562cb80796538157912 | Third Party Advisory |
| https://github.com/chillzhuang/SpringBlade | Product |
| https://github.com/chillzhuang/SpringBlade/issues/35 | Issue Tracking Third Party Advisory |
Configurations
History
11 Feb 2026, 19:28
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Bladex springblade
Bladex |
|
| References | () https://gist.github.com/old6ma/9c4d2ba32cd8f562cb80796538157912 - Third Party Advisory | |
| References | () https://github.com/chillzhuang/SpringBlade - Product | |
| References | () https://github.com/chillzhuang/SpringBlade/issues/35 - Issue Tracking, Third Party Advisory | |
| CPE | cpe:2.3:a:bladex:springblade:4.5.0:*:*:*:*:*:*:* |
23 Jan 2026, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-284 CWE-862 |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.9 |
23 Jan 2026, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-23 19:15
Updated : 2026-02-11 19:28
NVD link : CVE-2025-70983
Mitre link : CVE-2025-70983
CVE.ORG link : CVE-2025-70983
JSON object : View
Products Affected
bladex
- springblade
