CVE-2025-70560
Molecule · Boltz
A high-severity vulnerability has been identified in Molecule Boltz 2, potentially allowing for unauthorized system access or data manipulation.
Executive summary
Molecule Boltz 2 is affected by a high-severity vulnerability that could lead to a complete compromise of the application environment.
Vulnerability
While the technical specifics are limited in the summary, the CVSS score of 8.4 indicates a critical flaw, likely involving an unauthenticated attacker. The vulnerability exists within the core logic of the Boltz 2 application.
Business impact
The business impact of this vulnerability is high, as reflected by its CVSS score. Potential consequences include unauthorized access to proprietary data, loss of system integrity, and significant downtime. Organizations relying on Boltz 2 for critical operations face a high risk of service disruption.
Remediation
Immediate Action: Apply the security updates for Boltz 2 provided by Molecule immediately to close the security gap.
Proactive Monitoring: Enable detailed application logging and monitor for anomalous behavior, such as unexpected file modifications or unauthorized user creations.
Compensating Controls: Restrict network access to the Boltz 2 application using firewalls and ensure that the principle of least privilege is applied to all service accounts.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Immediate remediation is required. Administrators should prioritize the deployment of the vendor's patch to Boltz 2 instances to mitigate the risk of unauthorized access and maintain the security posture of their application stack.