CVE-2025-54598: Bevy
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows CSRF to delete all notifications via the /notifications/delete/ URI.
Affected products
- Bevy Bevy: up to and including 2025-06-24
Published 2025-08-27. Last modified 2026-06-17.