CVE-2025-2885
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Mar 27, 2025
Updated: Mar 28, 2025
CWE ID 352
Summary
CVE-2025-2885 is a vulnerability affecting tough, a popular blockchain client. The issue lies in the lack of validation for the root metadata version number, enabling an attacker to supply a fraudulent version number to the client. This manipulation can alter the version fetched by the client, potentially leading to security risks. Users are advised to upgrade to tough version 0.20.0 or later to mitigate this vulnerability, and developers of forked or derivative code must incorporate the necessary fixes.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress