CVE-2025-23027: Haydenbleasel Next-Forge
Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.
next-forge is a Next.js project boilerplate for modern web application. The BASEHUB_TOKEN commited in apps/web/.env.example. Users should avoid use of this token and should remove any access it may have in their systems.
Affected products
- Haydenbleasel Next-Forge: before 3.0.11 (fixed in 3.0.11)
Published 2025-01-13. Last modified 2026-06-17.