CVE-2025-6669 Details
Description
A vulnerability was found in gooaclok819 sublinkX up to 1.8. It has been declared as problematic. This vulnerability affects unknown code of the file middlewares/jwt.go. The manipulation with the input sublink leads to use of hard-coded cryptographic key . The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.9 is able to address this issue. The patch is identified as 778d26aef723daa58df98c8060c43f5bf5d1b10b. It is recommended to upgrade the affected component.
A vulnerability exists in gooaclok819 sublinkX versions through 1.8, where a hard-coded JSON Web Token (JWT) secret key is embedded in the middleware file 'jwt.go'. This flaw allows for the potential forgery of JWT tokens, bypassing authentication processes. The vulnerability can be exploited remotely, without any authentication requirements. Although the exploitation is considered complex, a public proof-of-concept is available.
Upgrade to gooaclok819 sublinkX version 1.9, which addresses this vulnerability by removing the hard-coded key and replacing it with a configurable option. The updated version is available on the project's GitHub release page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2025CISA-ADP
Assessed Jun 26, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/gooaclok819/sublinkX/commit/778d26aef723daa58df98c8060c43f5bf5d1b10b | [email protected] | Source CodeVendor |
| https://github.com/gooaclok819/sublinkX/issues/68 | [email protected] | |
| https://github.com/gooaclok819/sublinkX/issues/68#issuecomment-2957290524 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/gooaclok819/sublinkX/releases/tag/1.9 | [email protected] | Release NotesVendor |
| https://vuldb.com/?ctiid.313882 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.313882 | [email protected] | AdvisoryBundleExploitRemedy |
| https://vuldb.com/?submit.602368 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-320 | Key Management Errors | [email protected] |
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gooaclok819 sublinkX | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Jun 27, 2025 | CVE Modified | [email protected] |
| Jun 25, 2025 | New CVE Received | [email protected] |
Volerion