CVE-2025-70841Disclosure(amcoders / dokans)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data via direct request to /script/.env file. The exposed file contains Laravel application encryption key (APP_KEY), database credentials, SMTP/SendGrid API credentials, and internal configuration parameters, enabling complete system compromise including authentication bypass via session token forgery, direct database access to all tenant data, and email infrastructure takeover. Due to the multi-tenancy architecture, this vulnerability affects all tenants in the system.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dokans

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-03); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
dokans

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-03: 4Mentions · 2026-02-09: 1Technical Details · 2026-02-03: 3Technical Details · 2026-02-09: 102-0302-09
Signal classification1 categories
Disclosure
5100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-034
Disclosure4
2026-02-091
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2025-70841 Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data via direct request… https://www.cve.org/CVERecord?id=CVE-2025-70841

    Post summary

    The text announces CVE-2025-70841, noting that unauthenticated remote attackers can retrieve sensitive configuration data from Dokans 3.9.2 via direct requests, but provides no evidence of active exploitation, PoC, or mitigation.

    00010227
    56.5K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-70841 - Critical Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive application configuration data via direct request to /script/.env file... https://www.thehackerwire.com/vulnerability/CVE-2025-70841/ https://t.co/IXn1CdvLrh

    Post summary

    A new critical vulnerability (CVE-2025-70841) in Dokans Multi‑Tenancy based eCommerce Platform SaaS 3.9.2 allows unauthenticated attackers to read the .env configuration file via a direct request. No patch or evidence of active exploitation is provided.

    0000136
    113 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Disclosure

    CRITICAL ALERT: CVE-2025-70841 (CVSS 10.0) Dokans Multi-Tenancy SaaS 3.9.2 allows unauthenticated remote attackers to access .env files directly. 📂 ⚠️ Risk: Exposure of DB creds & APP_KEYs leading to full system compromise & account takeover. #InfoSec #CyberSecurity #Laravel #Vulnerability #Malware #CVE

    Post summary

    The post announces CVE‑2025‑70841 as a critical vulnerability allowing unauthenticated remote attackers to read .env files, exposing credentials and potentially compromising the system.

    0000061
    37 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-70841: CRITICAL] Critical security vulnerability in Dokans Multi-Tenancy eCommerce Platform SaaS 3.9.2 allows attackers to access sensitive data and compromise systems. #cybersecurity#cve,CVE-2025-70841,#cybersecurity https://cvefind.com/CVE-2025-70841

    Post summary

    A critical vulnerability (CVE‑2025‑70841) in Dokans Multi‑Tenancy eCommerce Platform SaaS 3.9.2 has been announced, enabling attackers to access sensitive data and compromise systems.

    0000058
    583 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-70841: n/a (CVSS: 10.0)... Dokans 3.9.2 leaks .env via /script/.env - trivial to grab APP_KEY for session forgery, DB creds for tenant data exfil,... https://zerodaysignal.com/vulnerability/CVE-2025-70841 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post discloses CVE‑2025‑70841 in Dokans 3.9.2, noting that the /script/.env endpoint leaks the .env file, enabling attackers to obtain the APP_KEY for session forgery and database credentials for data exfiltration.

    0000056
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appamcodersdokans3.9.2--

Explore more