CVE-2025-54428

Source
https://cve.org/CVERecord?id=CVE-2025-54428
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54428.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-54428
Aliases
  • GHSA-m253-qvcr-cr48
Published
2025-07-28T20:28:02.575Z
Modified
2026-04-02T12:53:45.769178Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
RevelaCode exposes Sensitive MongoDB Atlas URI in .env (potential credential leak)
Details

RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessible language. In versions below 1.0.1, a valid MongoDB Atlas URI with embedded username and password was accidentally committed to the public repository. This could allow unauthorized access to production or staging databases, potentially leading to data exfiltration, modification, or deletion. This is fixed in version 1.0.1. Workarounds include: immediately rotating credentials for the exposed database user, using a secret manager (like Vault, Doppler, AWS Secrets Manager, etc.) instead of storing secrets directly in code, or auditing recent access logs for suspicious activity.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54428.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-522"
    ]
}
References

Affected packages

Git / github.com/musombi123/revelacode-backend

Affected ranges

Type
GIT
Repo
https://github.com/musombi123/revelacode-backend
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54428.json"