CVE-2025-57806
Severity CVSS v4.0:
MEDIUM
Type:
CWE-312
Cleartext Storage of Sensitive Information
Publication date:
03/09/2025
Last modified:
04/09/2025
Description
Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, including API keys, in a local SQLite database without encryption. This behavior was not clearly documented outside of the database architecture page. Users were not given the ability to configure the database location, allowing anyone with access to the container or host filesystem to retrieve sensitive data in plaintext by accessing the .db file. This is fixed in version 1.0.0.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM