Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remote attackers to exploit the fixed key to generate verification information, thereby logging into the system as any user. Attacker must first obtain an user ID in order to exploit this vulnerability.
References
Configurations
No configuration.
History
17 Oct 2025, 04:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-17 04:16
Updated : 2025-10-21 19:31
NVD link : CVE-2025-11899
Mitre link : CVE-2025-11899
CVE.ORG link : CVE-2025-11899
JSON object : View
Products Affected
No product.
CWE
CWE-321
Use of Hard-coded Cryptographic Key
