CVE-2025-23027
Severity CVSS v4.0:
MEDIUM
Type:
CWE-312
Cleartext Storage of Sensitive Information
Publication date:
13/01/2025
Last modified:
13/01/2025
Description
next-forge is a Next.js project boilerplate for modern web application. The BASEHUB_TOKEN commited in apps/web/.env.example. Users should avoid use of this token and should remove any access it may have in their systems.
Impact
Base Score 4.0
6.30
Severity 4.0
MEDIUM