—
GO-2025-4269
SQLE's JWT Secret Handler can be manipulated to use hard-coded cryptographic key in github.com/actiontech/sqle
Details
SQLE's JWT Secret Handler can be manipulated to use hard-coded cryptographic key in github.com/actiontech/sqle
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/actiontech/sqle
Introduced in:
0No fixed version published yet for github.com/actiontech/sqle (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/advisories/GHSA-43h9-hc38-qph5[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2025-15107[ADVISORY]
- https://github.com/actiontech/sqle/issues/3186[REPORT]
- https://github.com/actiontech/sqle/blob/4714f83f33e0d7aa647036eb756e928aa4174014/sqle/utils/jwt.go#L9[WEB]
- https://github.com/actiontech/sqle/milestone/53[WEB]
- https://vuldb.com/?ctiid.338478[WEB]
- https://vuldb.com/?id.338478[WEB]
- https://vuldb.com/?submit.710380[WEB]