CVE-2025-57806

Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, including API keys, in a local SQLite database without encryption. This behavior was not clearly documented outside of the database architecture page. Users were not given the ability to configure the database location, allowing anyone with access to the container or host filesystem to retrieve sensitive data in plaintext by accessing the .db file. This is fixed in version 1.0.0.
CVSS

No CVSS.

Configurations

No configuration.

History

03 Sep 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-03 01:15

Updated : 2025-09-04 15:36


NVD link : CVE-2025-57806

Mitre link : CVE-2025-57806

CVE.ORG link : CVE-2025-57806


JSON object : View

Products Affected

No product.

CWE
CWE-312

Cleartext Storage of Sensitive Information

CWE-522

Insufficiently Protected Credentials