CVE-2025-60949
Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker could send requests to configuration files and obtain leaked secrets. Fixed in 8.1.0 alpha.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-082-01.json, https://www.cve.org/CVERecord?id=CVE-2025-60949, https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/60xxx/CVE-2025-60949.json, https://nvd.nist.gov/vuln/detail/CVE-2025-60949, https://github.com/csprousers/csweb/commit/eba0b59a243390a1a4f9524cce6dbc0314bf0d91, https://github.com/hx381/cspro-exploits