Vulnerability Description
Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Vexa transcription-collector service exposes an internal endpoint `GET /internal/transcripts/{meeting_id}` that returns transcript data for any meeting without any authentication or authorization checks. An unauthenticated attacker can enumerate all meeting IDs, access any user's meeting transcripts without credentials, and steal confidential business conversations, passwords, and/or PII. Version 0.10.0-260419-1910 patches the issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vexa | Vexa | <= 0.10 |
Related Weaknesses (CWE)
References
- https://github.com/Vexa-ai/vexa/security/advisories/GHSA-w73r-2449-qwghExploitVendor Advisory
- https://github.com/Vexa-ai/vexa/security/advisories/GHSA-w73r-2449-qwghExploitVendor Advisory
FAQ
What is CVE-2026-25058?
CVE-2026-25058 is a vulnerability with a CVSS score of 7.5 (HIGH). Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Vexa transcription-collector service exposes an internal endpoint `GET /internal/t...
How severe is CVE-2026-25058?
CVE-2026-25058 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-25058?
Check the references section above for vendor advisories and patch information. Affected products include: Vexa Vexa.