CVE-2025-7080 Details
Description
A vulnerability, which was classified as problematic, was found in Done-0 Jank up to 322caebbad10568460364b9667aa62c3080bfc17. Affected is an unknown function of the file internal/utils/jwt_utils.go of the component JWT Token Handler. The manipulation of the argument accessSecret/refreshSecret with the input jank-blog-secret/jank-blog-refresh-secret leads to use of hard-coded password. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
A vulnerability exists in Done-0 Jank versions up to 322caebbad10568460364b9667aa62c3080bfc17, specifically within the JWT Token Handler component. The issue arises from hard-coded secret keys for access and refresh tokens in the file internal/utils/jwt_utils.go. This vulnerability allows remote attackers to forge valid JWT tokens, bypass authentication, and potentially manipulate content by creating posts or comments. The exploitation of this vulnerability is considered difficult due to the high complexity of the attack.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 6, 2025CISA-ADP
Assessed Jul 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Done-0/Jank/issues/9 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/?ctiid.314994 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.314994 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.603746 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-255 | Credentials Management Errors | [email protected] |
| CWE-259 | Use of Hard-coded Password | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Done-0 Jank | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Jul 6, 2025 | New CVE Received | [email protected] |
Volerion