CVE-2025-13804: NutzBoot vulnerable to information disclosure
(updated )
A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT. The impacted element is an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthModule.java of the component Ethereum Wallet Handler. Performing manipulation results in information disclosure. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.
References
- github.com/Xzzz111/exps/blob/main/archives/nutzboot-InfoLeak-1/report.md
- github.com/Xzzz111/exps/blob/main/archives/nutzboot-InfoLeak-1/report.md
- github.com/advisories/GHSA-qp56-qj59-hjf8
- github.com/nutzam/nutzboot
- nvd.nist.gov/vuln/detail/CVE-2025-13804
- vuldb.com/?ctiid.333814
- vuldb.com/?id.333814
- vuldb.com/?submit.692050
Code Behaviors & Features
Detect and mitigate CVE-2025-13804 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →