CVE-2025-65957: Intercore-Productions Core-Bot

High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Core Bot Is an Open Source discord bot made for maple hospital servers. Prior to commit dffe050, the API keys (SUPABASE_API_KEY, TOKEN) are loaded using environment variables, but there are cases in code (error handling, summaries, webhooks) where configuration summaries may inadvertently leak sensitive data (e.g., by failing to redact data in summary embeds or logs). This issue has been patched via commit dffe050.

Affected products

  • Intercore-Productions Core-Bot: before dffe050d565a580edfcd0242efa45da88ab31260 (fixed in dffe050d565a580edfcd0242efa45da88ab31260)

Published 2025-11-26. Last modified 2026-06-17.