CVE-2025-23027: Haydenbleasel Next-Forge

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

next-forge is a Next.js project boilerplate for modern web application. The BASEHUB_TOKEN commited in apps/web/.env.example. Users should avoid use of this token and should remove any access it may have in their systems.

Affected products

Published 2025-01-13. Last modified 2026-06-17.