CVE-2025-63662
System Prompt Leakage via Insecure API Permissions
01Record
| Identifier | CVE-2025-63662 |
|---|---|
| Project | GT Edge AI Platform |
| Component | /api/v1/agents |
| CWE | CWE-200 |
| CVSS | 7.5 |
| Disclosed | 2025-12-22 |
| Writeup | Link |
02Detail
Description: Insecure permissions in the /api/v1/agents API endpoint allow authenticated attackers to access sensitive information including system prompts and confidential AI agent configurations.
Impact: Information Disclosure, Privilege Escalation
Discovered by Peyton Kennedy (p80n), Richard Medlin.