CVE-2025-70983

Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bladex:springblade:4.5.0:*:*:*:*:*:*:*

History

11 Feb 2026, 19:28

Type Values Removed Values Added
First Time Bladex springblade
Bladex
References () https://gist.github.com/old6ma/9c4d2ba32cd8f562cb80796538157912 - () https://gist.github.com/old6ma/9c4d2ba32cd8f562cb80796538157912 - Third Party Advisory
References () https://github.com/chillzhuang/SpringBlade - () https://github.com/chillzhuang/SpringBlade - Product
References () https://github.com/chillzhuang/SpringBlade/issues/35 - () https://github.com/chillzhuang/SpringBlade/issues/35 - Issue Tracking, Third Party Advisory
CPE cpe:2.3:a:bladex:springblade:4.5.0:*:*:*:*:*:*:*

23 Jan 2026, 20:15

Type Values Removed Values Added
CWE CWE-284
CWE-862
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.9

23 Jan 2026, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-23 19:15

Updated : 2026-02-11 19:28


NVD link : CVE-2025-70983

Mitre link : CVE-2025-70983

CVE.ORG link : CVE-2025-70983


JSON object : View

Products Affected

bladex

  • springblade
CWE
CWE-284

Improper Access Control

CWE-862

Missing Authorization