VYPR
Medium severity6.5NVD Advisory· Published Aug 27, 2025· Updated Jun 17, 2026

CVE-2025-54598

CVE-2025-54598

Description

The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows CSRF to delete all notifications via the /notifications/delete/ URI.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Bevy/Bevy Eventllm-fuzzy
    Range: <=2025-07-22
  • eBay/eBay Seller Eventsdescription
  • cpe:2.3:a:bevy:bevy:*:*:*:*:*:*:*:*
    Range: <=2025-06-24

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.