CVE-2025-27611
Aliases:GHSA-xq7p-g2vc-g82p
Advisory lineage Upstream: 0 Downstream: 2
Downstream
Deferred
Published: 30 Apr 2025, 19:36
Last modified:01 May 2025, 18:49
Vulnerability Summary
Overall Risk (default)
medium
35/100 CVSS Score
8.7 HIGH
v4.0 (cve.org)
EPSS Score
0.38% LOW
0% probability +0.26%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
30 Apr 2025, 19:36
Published
Vulnerability first disclosed
01 May 2025, 18:49
Last Modified
Vulnerability information updated
Description
base-x is a base encoder and decoder of any given alphabet using bitcoin style leading zero compression. Versions 4.0.0, 5.0.0, and all prior to 3.0.11, are vulnerable to attackers potentially deceiving users into sending funds to an unintended address. This issue has been patched in versions 3.0.11, 4.0.1, and 5.0.1.
CVSS Metrics
- v4.0•HIGH•Score: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- v4.0•HIGH•Score: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Trends
Current EPSS score: 0.38%• Percentile: 60%
Techniques & Countermeasures
- CWE-1007•Insufficient Visual Distinction of Homoglyphs Presented to User
The product displays information or identifiers to a user, but the display mechanism does not make it easy for the user to distinguish between visually similar or identical glyphs (homoglyphs), which may cause the user to misinterpret a glyph and perform an unintended, insecure action.
Affected Systems
- cryptocoinjs•base-x
= 5.0.0 | = 4.0.0 | < 3.0.11
- Npm•base-x
≥ 5.0.0, < 5.0.1 | ≥ 4.0.0, < 4.0.1 | < 3.0.11