-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from exposed encoding/decoding maps in the codebase. The commit diff shows these cryptographic operations are handled in FileManager.py's Encoded functions. The advisory explicitly states the encoding maps were visible in code (CWE-323 context), and these functions directly implement the vulnerable encoding/decoding logic. The high confidence comes from: 1) Advisory directly referencing encoding map exposure 2) CWE-323 alignment with static cryptographic material reuse 3) Functions' responsibility for cryptographic operations 4) Post-install script requirement suggesting key/map generation was moved out of code in the patch.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| PheonixAppAPI | pip | < 0.2.5 | 0.2.5 |
Ongoing coverage of React2Shell