← All research

CVE-2025-63662

System Prompt Leakage via Insecure API Permissions

01Record

IdentifierCVE-2025-63662
ProjectGT Edge AI Platform
Component/api/v1/agents
CWECWE-200
CVSS7.5
Disclosed2025-12-22
WriteupLink

02Detail

Description: Insecure permissions in the /api/v1/agents API endpoint allow authenticated attackers to access sensitive information including system prompts and confidential AI agent configurations.

Impact: Information Disclosure, Privilege Escalation

Discovered by Peyton Kennedy (p80n), Richard Medlin.