CVE-2025-55306 Details
Description
GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API keys and authentication tokens may be exposed if environment variables are misconfigured. Unauthorized users could gain access to cloud resources (Google Cloud, Firebase, GitHub, etc.).
An authentication bypass vulnerability has been identified in the GenX FX backend, specifically in versions prior to 1.0.1. This vulnerability allows for the exposure of API keys and authentication tokens if environment variables are not properly configured. Unauthorized users could potentially access various cloud resources, including Google Cloud, Firebase, and GitHub. The issue primarily affects developers who sync repositories with environment variable values or leave API keys in configuration files, as well as deployments on Firebase or Cloud Run that do not integrate with the Secret Manager.
To address this vulnerability, users should update to GenX FX version 1.0.1 or later, after cleaning up any exposed secrets and integrating with Firebase. It is also recommended to store sensitive credentials in Google Cloud Secret Manager for production environments and to use secure .env files for local development. Developers should rotate any keys that may have been exposed and delete old Firebase, GitLab, or GitHub tokens before regenerating them.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 19, 2025CISA-ADP
Assessed Aug 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Mouy-leng/GenX_FX/security/advisories/GHSA-2xjq-pvwj-mvm6 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-522 | Insufficiently Protected Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Mouy-leng GenX_FX | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 19, 2025 | New CVE Received | [email protected] |
Volerion