Impact
A weakness in PentestGPT’s core language integration file, langfuse.py, embeds static API credentials. This flaw permits a remote adversary to retrieve telemetry gathered by the tool, exposing privacy‑sensitive user data. The vulnerability aligns with attempts to misuse hard‑coded secrets (CWE‑798) and directly reveals protected information.
Affected Systems
The vulnerability affects the open‑source PentestGPT tool, version 1.0.0, which includes the langfuse.py file with hard‑coded API credentials. No specific vendor was listed, but individuals using this version of the product are at risk.
Risk and Exploitability
The EPSS score is <1%, and the CVSS score is 7.5, indicating a high severity vulnerability. The attack vector is inferred to be remote, as the hard‑coded credentials allow an attacker to access the telemetry endpoint if it is exposed or reachable. While the exact exploitation conditions are not detailed, the exposed credential could enable retrieval of sensitive user telemetry, leading to confidentiality compromise. Given the CVSS score, the risk level is high, but the potential impact warrants prompt remediation.
OpenCVE Enrichment