CVE Explorer
CVE-2025-65109
Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and Minder Go versions from 0.0.72 to 0.0.83, Minder users may fetch content in the context of the Minder server, which may include URLs which the user would not normally have access to. This issue has been patched in Minder Helm version 0.20250203.3849+ref.fdc94f0 and Minder Go version 0.0.84.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"minder","vendor":"mindersec","versions":[{"status":"affected","version":"Helm = 0.20241106.3386+ref.2507dbf"},{"status":"affected","version":"Go >= 0.0.72, < 0.0.84"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:5c0a820a7a8bfed06e766d0df472b0eadd2ca4ca7fd722bc8c13e06b495147da · sha256:724b119998648541… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.5,"baseSeverity":"HIGH","privilegesRequired":"LOW","subAvailabilityImpact":"LOW","subConfidentialityImpact":"HIGH","subIntegrityImpact":"LOW","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:5c0a820a7a8bfed06e766d0df472b0eadd2ca4ca7fd722bc8c13e06b495147da · sha256:724b119998648541… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-830","description":"CWE-830: Inclusion of Web Functionality from an Untrusted Source","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5c0a820a7a8bfed06e766d0df472b0eadd2ca4ca7fd722bc8c13e06b495147da · sha256:724b119998648541… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/mindersec/minder/commit/f770400923984649a287d7215410ef108e845af8","tags":["x_refsource_MISC"],"url":"https://github.com/mindersec/minder/commit/f770400923984649a287d7215410ef108e845af8"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5c0a820a7a8bfed06e766d0df472b0eadd2ca4ca7fd722bc8c13e06b495147da · sha256:724b119998648541… · /containers/cna/references/1
{"name":"https://github.com/mindersec/minder/security/advisories/GHSA-6xvf-4vh9-mw47","tags":["x_refsource_CONFIRM"],"url":"https://github.com/mindersec/minder/security/advisories/GHSA-6xvf-4vh9-mw47"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5c0a820a7a8bfed06e766d0df472b0eadd2ca4ca7fd722bc8c13e06b495147da · sha256:724b119998648541… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.