CVE-2025-54872

onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd89 contain a baked-in tor image if the secrets were copied from an existing onion domain. A website could be compromised if a user shared the baked-in image, or if someone were able to acquire access to the user's device outside of a containerized environment. This is fixed by commit bc9ba0fd.
CVSS

No CVSS.

Configurations

No configuration.

History

06 Aug 2025, 20:23

Type Values Removed Values Added
Summary
  • (es) onion-site-template es una muestra completa, escalable y autoalojada de un servicio oculto de Tor. Las versiones que incluyen el commit 3196bd89 contienen una imagen de Tor preinstalada si los secretos se copiaron de un dominio onion existente. Un sitio web podría verse comprometido si un usuario compartiera la imagen preinstalada o si alguien pudiera acceder al dispositivo del usuario fuera de un entorno contenedorizado. Esto se solucionó con el commit bc9ba0fd.

06 Aug 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-06 00:15

Updated : 2025-08-06 20:23


NVD link : CVE-2025-54872

Mitre link : CVE-2025-54872

CVE.ORG link : CVE-2025-54872


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials