cvedb.io
CVE-2026-25058
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2026-04-20T16:16:41.763 · Last modified 2026-06-17T10:24:03.563

Summary

Vexa is an open-source, self-hostable meeting bot API and meeting transcription API. Prior to 0.10.0-260419-1910, the Vexa transcription-collector service exposes an internal endpoint `GET /internal/transcripts/{meeting_id}` that returns transcript data for any meeting without any authentication or authorization checks. An unauthenticated attacker can enumerate all meeting IDs, access any user's meeting transcripts without credentials, and steal confidential business conversations, passwords, and/or PII. Version 0.10.0-260419-1910 patches the issue.

Affected products

vexa — vexa

Does this affect you?

Add your gear to cvedb and we'll alert you only when vexa ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.