CVE-2025-27611

Aliases:GHSA-xq7p-g2vc-g82p
Advisory lineage Upstream: 0 Downstream: 2
Deferred
Published: 30 Apr 2025, 19:36
Last modified:01 May 2025, 18:49

Vulnerability Summary

Overall Risk (default)
medium
35/100
CVSS Score
8.7 HIGH
v4.0 (cve.org)
EPSS Score
0.38% LOW
0% probability +0.26%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Apr 2025, 19:36
Published
Vulnerability first disclosed
01 May 2025, 18:49
Last Modified
Vulnerability information updated

Description

base-x is a base encoder and decoder of any given alphabet using bitcoin style leading zero compression. Versions 4.0.0, 5.0.0, and all prior to 3.0.11, are vulnerable to attackers potentially deceiving users into sending funds to an unintended address. This issue has been patched in versions 3.0.11, 4.0.1, and 5.0.1.

CVSS Metrics

  • v4.0HIGHScore: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
  • v4.0HIGHScore: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Trends

Current EPSS score: 0.38% Percentile: 60%

Techniques & Countermeasures

  • CWE-1007Insufficient Visual Distinction of Homoglyphs Presented to User

    The product displays information or identifiers to a user, but the display mechanism does not make it easy for the user to distinguish between visually similar or identical glyphs (homoglyphs), which may cause the user to misinterpret a glyph and perform an unintended, insecure action.

Affected Systems

  • cryptocoinjsbase-x

    = 5.0.0 | = 4.0.0 | < 3.0.11

  • Npmbase-x

    ≥ 5.0.0, < 5.0.1 | ≥ 4.0.0, < 4.0.1 | < 3.0.11

References (4)