Impact
A weakness in PentestGPT’s core language integration file, langfuse.py, embeds static API credentials. This flaw permits a remote adversary to retrieve telemetry gathered by the tool, exposing privacy‑sensitive user data. The vulnerability aligns with attempts to misuse hard‑coded secrets (CWE‑798) and directly reveals protected information (CWE‑200).
Affected Systems
The vulnerability affects the open‑source PentestGPT tool, version 1.0.0, which includes the langfuse.py file with hard‑coded API credentials. No specific vendor was listed, but individuals using this version of the product are at risk.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, as the hard‑coded credentials allow an attacker to access the telemetry endpoint if it is exposed or reachable. While the exact exploitation conditions are not detailed, the exposed credential could enable retrieval of sensitive user telemetry, leading to confidentiality compromise. Given the lack of a publicly documented exploit, the immediate risk level is moderate, but the potential impact warrants prompt remediation.
OpenCVE Enrichment