eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is exposed in .env. A valid Supabase URI with embedded username and password will allow an attacker complete unauthorized access and control over database and user data. This could lead to data exfiltration, modification or deletion.
History

Thu, 21 Aug 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 21 Aug 2025 16:30:00 +0000

Type Values Removed Values Added
Description eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is exposed in .env. A valid Supabase URI with embedded username and password will allow an attacker complete unauthorized access and control over database and user data. This could lead to data exfiltration, modification or deletion.
Title eslint-ban-moment exposed a sensitive Supabase URI in .env (Credential leak)
Weaknesses CWE-260
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-21T16:14:29.391Z

Updated: 2025-08-21T17:31:58.060Z

Reserved: 2025-08-19T15:16:22.916Z

Link: CVE-2025-57754

cve-icon Vulnrichment

Updated: 2025-08-21T17:23:56.292Z

cve-icon NVD

Status : Received

Published: 2025-08-21T17:15:31.420

Modified: 2025-08-21T17:15:31.420

Link: CVE-2025-57754

cve-icon Redhat

No data.