CVE-2025-23027 Details
Description
next-forge is a Next.js project boilerplate for modern web application. The BASEHUB_TOKEN commited in apps/web/.env.example. Users should avoid use of this token and should remove any access it may have in their systems.
A vulnerability exists in the Next.js project boilerplate 'next-forge' due to the inclusion of a sensitive token, BASEHUB_TOKEN, in the file 'apps/web/.env.example'. This token should not be used and any access it may have granted should be revoked.
Users should remove the BASEHUB_TOKEN from their environment files and revoke any access it may have granted. The vulnerability has been patched in version 3.0.11.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 13, 2025CISA-ADP
Assessed Jan 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/haydenbleasel/next-forge/commit/239a98f2c308a51d626ae0613102917f82603c1c | [email protected] | Source CodeVendor |
| https://github.com/haydenbleasel/next-forge/security/advisories/GHSA-wppx-qmqh-9h33 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-312 | Cleartext Storage of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vercel next-forge | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 13, 2025 | New CVE Received | [email protected] |
Volerion