Core Bot Is an Open Source discord bot made for maple hospital servers. Prior to commit dffe050, the API keys (SUPABASE_API_KEY, TOKEN) are loaded using environment variables, but there are cases in code (error handling, summaries, webhooks) where configuration summaries may inadvertently leak sensitive data (e.g., by failing to redact data in summary embeds or logs). This issue has been patched via commit dffe050.
History

Tue, 25 Nov 2025 23:45:00 +0000

Type Values Removed Values Added
Description Core Bot Is an Open Source discord bot made for maple hospital servers. Prior to commit dffe050, the API keys (SUPABASE_API_KEY, TOKEN) are loaded using environment variables, but there are cases in code (error handling, summaries, webhooks) where configuration summaries may inadvertently leak sensitive data (e.g., by failing to redact data in summary embeds or logs). This issue has been patched via commit dffe050.
Title Core Bot is Leaking Sensitive Credentials in Logs, Errors, and Messages
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:L/SI:H/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-25T23:33:09.921Z

Updated: 2025-11-26T16:11:42.244Z

Reserved: 2025-11-18T16:14:56.693Z

Link: CVE-2025-65957

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-26T00:15:50.937

Modified: 2025-11-26T00:15:50.937

Link: CVE-2025-65957

cve-icon Redhat

No data.