Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      GitHub’s CEO Thomas Dohmke steps down, triggering tighter integration of company within Microsoft

      August 12, 2025

      bitHuman launches SDK for creating AI avatars

      August 12, 2025

      Designing With AI, Not Around It: Practical Advanced Techniques For Product Design Use Cases

      August 11, 2025

      Why Companies Are Investing in AI-Powered React.js Development Services in 2025

      August 11, 2025

      I found a Google Maps alternative that won’t track you or drain your battery – and it’s free

      August 12, 2025

      I tested this new AI podcast tool to see if it can beat NotebookLM – here’s how it did

      August 12, 2025

      Microsoft’s new update makes your taskbar a productivity hub – here’s how

      August 12, 2025

      Save $50 on the OnePlus Pad 3 plus get a free gift – here’s the deal

      August 12, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Laravel Global Scopes: Automatic Query Filtering

      August 12, 2025
      Recent

      Laravel Global Scopes: Automatic Query Filtering

      August 12, 2025

      Building MCP Servers in PHP

      August 12, 2025

      Filament v4 is Stable!

      August 12, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      I Asked OpenAI’s New Open-Source AI Model to Complete a Children’s School Test — Is It Smarter Than a 10-Year-Old?

      August 12, 2025
      Recent

      I Asked OpenAI’s New Open-Source AI Model to Complete a Children’s School Test — Is It Smarter Than a 10-Year-Old?

      August 12, 2025

      Madden NFL 26 Leads This Week’s Xbox Drops—But Don’t Miss These Hidden Gems

      August 12, 2025

      ASUS G14 Bulked Up for 2025—Still Sexy, Just a Bit Chonkier

      August 12, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2025-47274 – ToolHive Inadvertent Secrets Storage Vulnerability

    CVE-2025-47274 – ToolHive Inadvertent Secrets Storage Vulnerability

    May 12, 2025

    CVE ID : CVE-2025-47274

    Published : May 12, 2025, 3:16 p.m. | 1 hour, 18 minutes ago

    Description : ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Due to the ordering of code used to start an MCP server container, versions of ToolHive prior to 0.0.33 inadvertently store secrets in the run config files which are used to restart stopped containers. This means that an attacker who has access to the home folder of the user who starts the MCP server can read secrets without needing access to the secrets store itself. This only applies to secrets which were used in containers whose run configs exist at a point in time – other secrets remaining inaccessible. ToolHive 0.0.33 fixes the issue. Some workarounds are available. Stop and delete any running MCP servers, or manually remove any runconfigs from `$HOME/Library/Application Support/toolhive/runconfigs/` (macOS) or `$HOME/.state/toolhive/runconfigs/` (Linux).

    Severity: 0.0 | NA

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCVE-2025-44022 – Vvveb CMS Remote Code Execution
    Next Article CVE-2025-46718 – “sudo-rs Sudo Privilege Listing Vulnerability”

    Related Posts

    Development

    Update WinRAR tools now: RomCom and others exploiting zero-day vulnerability

    August 12, 2025
    Development

    WinRAR zero-day exploited in espionage attacks against high-value targets

    August 12, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    CVE-2025-6916 – TOTOLINK T6 Local Network Authentication Bypass

    Common Vulnerabilities and Exposures (CVEs)

    May 2025 Baseline monthly digest

    Development

    Key Metrics That Can Make or Break Your Startup

    Development

    CVE-2025-54446 – Samsung MagicINFO 9 Server Path Traversal

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    KL-001-2025-009: Schneider Electric EcoStruxure IT Data Center Expert Remote Command Execution

    July 10, 2025

    KL-001-2025-009: Schneider Electric EcoStruxure IT Data Center Expert Remote Command Execution

    Full Disclosure
    mailing list archives
    From: KoreLogic Disclosures via Fulldisclosure
    Date: Wed, 9 Jul 2025 17:16:55 -0500
    KL-001-2025-009: Schneider Electric EcoStruxu …
    Read more

    Published Date:
    Jul 09, 2025 (6 hours, 15 minutes ago)

    Vulnerabilities has been mentioned in this article.

    CVE-2025-8831 – Linksys Wireless Router Remote Management Stack Buffer Overflow Vulnerability

    August 11, 2025

    CVE-2025-2254 – GitLab Cross-Site Scripting (XSS) Vulnerability

    June 12, 2025

    CVE-2025-22460 – Ivanti Cloud Services Privilege Escalation Vulnerability

    May 13, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.