Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2025-57754
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
eslint-ban-moment exposed a sensitive Supabase URI in .env (Credential leak)
Source: NVD (National Vulnerability Database)
Vulnerability Description
eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is exposed in .env. A valid Supabase URI with embedded username and password will allow an attacker complete unauthorized access and control over database and user data. This could lead to data exfiltration, modification or deletion.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
配置文件中存储口令
Source: NVD (National Vulnerability Database)
Vulnerability Title
eslint-ban-moment 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
eslint-ban-moment是Kristófer Fannar Björnsson个人开发者的一个应用程序。 eslint-ban-moment 3.0.0及之前版本存在安全漏洞,该漏洞源于.env文件中暴露敏感Supabase URI,可能导致数据渗漏、修改或删除。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
kristoferfannareslint-ban-moment <= 3.0.0 -
II. Public POCs for CVE-2025-57754
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2025-57754
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2025-57754

No comments yet


Leave a comment