Medium severity6.5NVD Advisory· Published Aug 27, 2025· Updated Jun 17, 2026
CVE-2025-54598
CVE-2025-54598
Description
The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows CSRF to delete all notifications via the /notifications/delete/ URI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <=2025-07-22
- eBay/eBay Seller Eventsdescription
Patches
Vulnerability mechanics
References
3- gist.github.com/deep1chil/057b63e62d4db6158a3ee28995fc246fnvdExploitThird Party Advisory
- bevy.com/b/events-and-groupsnvdProduct
- github.com/actuator/cve/blob/main/Kuwfi/CVE-2025-43985.txtnvdNot Applicable
News mentions
0No linked articles in our index yet.