CVE-2025-67745CWE-402

Myhoard logs backup encryption key in plain text

High ยท published December 18, 2025

CVSS v3.1
7.1
EPSS
0%
Percentile
4.8
In the wild
Unconfirmed
What it is

โšก A backup logging blunder can expose your encryption keys! MyHoard versions 1.0.1 through 1.2.9 might accidentally spill critical secrets in their logs โ€” like leaving the front door wide open during a home renovation. ๐Ÿก๐Ÿ’” Think of MyHoard as a vault that stores your valuable documents. If that vault logs the combination on a sticky note and leaves it out in the open, anyone could waltz in and take what they want! This oversight could lead to an attacker accessing your MySQL backups and sensitive data โ€” with your encryption keys laid bare, they could decrypt everything and wreak havoc. Imagine losing your most critical information because someone snooped at those logs!

Put simply

Think of MyHoard as a vault that stores your valuable documents. If that vault logs the combination on a sticky note and leaves it out in the open, anyone could waltz in and take what they want! This vulnerability arises from MyHoard improperly logging backup details, including sensitive encryption keys, in versions 1.0.1 through 1.2.9. The logging mechanism fails to secure this data, allowing potential exposure if the logs are accessed by unauthorized users.

What to do

This oversight could lead to an attacker accessing your MySQL backups and sensitive data โ€” with your encryption keys laid bare, they could decrypt everything and wreak havoc. Imagine losing your most critical information because someone snooped at those logs! Upgrade your MyHoard to version 1.3.0 immediately to close this security gap. As a temporary workaround, redirect logs to /dev/null to prevent sensitive information from being stored. Regularly audit your logging practices for security best practices! You've got this! By following these steps, you can secure your backups and keep your data safe. ๐Ÿ›ก๏ธ๐Ÿš€

The record
Technical detail
CVSS v3.1
7.1 ยท HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00154 ยท 4.8th percentile
Weakness
CWE-402 ยท Transmission of Private Resources into a New Sphere ('Resource Leak')
Published
2025-12-18T18:37Z
EPSS history
Timeline
  • 18 DEC 18:37Z
    Myhoard logs backup encryption key in plain text
    cvelistv5