CVE-2025-10560
published 2026-06-18CVE-2025-10560: Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries. The…
PriorityP259critical9.3CVSS 4.0
AVNACLATNPRNUINVCHVINVANSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.39%
30.6th percentile
Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries. The exposed credentials included AWS access keys, S3 bucket names, and related cloud access information. The originally exposed AWS credentials authenticated as the AWS account root identity and provided access to Worksnaps production cloud resources, including S3 buckets containing sensitive data such as screenshots of user desktops. An attacker with access to the affected client binaries could extract or recover the credentials and use them to access affected Worksnaps cloud resources.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| silver_leaf_technologies_inc | worksnaps.net_worksnaps | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Silver Leaf Worksnaps.net Worksnaps prior 1.6.202602 AWS Credential hard-coded credentials
vuldb·2026-06-18
CVE-2025-10560 [CRITICAL] Silver Leaf Worksnaps.net Worksnaps prior 1.6.202602 AWS Credential hard-coded credentials
A vulnerability was found in Silver Leaf Worksnaps.net Worksnaps. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component AWS Credential Handler. Executing a manipulation can lead to hard-coded credentials.
This vulnerability is handled as CVE-2025-10560. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
GHSA
Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries.
ghsa_unreviewed·2026-06-18
CVE-2025-10560 [CRITICAL] CWE-798 Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries.
Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps client application binaries. The exposed credentials included AWS access keys, S3 bucket names, and related cloud access information. The originally exposed AWS credentials authenticated as the AWS account root identity and provided access to Worksnaps production cloud resources, including S3 buckets containing sensitive data such as screenshots of user desktops. An attacker with access to the affected client binaries could extract or recover the credentials and use them to access affected Worksnaps cloud resources.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-18
Published