CVE-2025-57806
Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, including API keys, in a local SQLite database without encryption. This behavior was not clearly documented outside of the database architecture page. Users were not given the ability to configure the database location, allowing anyone with access to the container or host filesystem to retrieve sensitive data in plaintext by accessing the .db file. This is fixed in version 1.0.0.
- Affected products
- Local-Deep-Research
- Fix
- Available
- CVSS 4.0
- 6.9 MEDIUM
- EPSS
- 0.1% (0th percentile)
- Weakness
- CWE-312, CWE-522
- NVD status
- Deferred
- Published
- 2025-09-03
No indexed exploits for CVE-2025-57806 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-57806 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.