CVE-2025-62645: Rbi Restaurant Brands International Assistant
Critical severity, CVSS 9.9. EPSS: 0.7% chance of exploitation in the next 30 days.
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform via the createToken GraphQL mutation.
Affected products
- Rbi Restaurant Brands International Assistant: up to and including 2025-09-06
Published 2025-10-17. Last modified 2026-10-08.