CVE-2025-10080
A vulnerability has been found in running-elephant Datart up to 1.0.0-rc3. Affected by this issue is the function getTokensecret of the file datart/security/src/main/java/datart/security/util/AESUtil.java of the component API. The manipulation leads to use of hard-coded cryptographic key . The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
- Affected products
- Datart
- Fix
- Available
- CVSS 3.1
- 3.1 LOW
- EPSS
- 0.2% (15th percentile)
- Weakness
- CWE-320, CWE-321
- NVD status
- Deferred
- Published
- 2025-09-08
CVE-2025-10080 at NVD
No indexed exploits for CVE-2025-10080 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-10080 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.