CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.8. It affects GitHub. Public exploit code or proof-of-concept references have been detected in its references.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
GitHub PoC Links
Note: these links are listed for security research and verification purposes only.
CVE
CVE-2025-58401
Severity
MEDIUM
CVSS
6.8
EPSS
0.09%
GitHub
Original NVD Description
Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account.