No advisories yet.
Solution
Brightpick AI has updated their backend in Mission Control to release 1.67.0 to mitigate these vulnerabilities as of February 04, 2026. Users running Mission Control 1.67.0 or later are mitigated.
Workaround
Users of the affected products are encouraged to contact Brightpick AI https://brightpick.ai/contact-us/ for additional information.
Thu, 25 Jun 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle. | The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Brightpick AI's documentation portal. |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 17 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 15 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Brightpick Ai
Brightpick Ai mission Control |
|
| Vendors & Products |
Brightpick Ai
Brightpick Ai mission Control |
Fri, 14 Nov 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle. | |
| Title | Brightpick Mission Control / Internal Logic Control Unprotected Transport of Credentials | |
| Weaknesses | CWE-523 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-06-25T22:17:51.017Z
Reserved: 2025-10-29T17:40:55.209Z
Link: CVE-2025-64308
Updated: 2025-11-17T16:52:34.090Z
Status : Deferred
Published: 2025-11-15T00:15:47.893
Modified: 2026-06-17T09:54:11.013
Link: CVE-2025-64308
No data.
OpenCVE Enrichment
Updated: 2025-11-15T22:07:29Z