CVE-2026-25146 PUBLISHED

OpenEMR's payments gateway_api_key secret rendered into client JS code

Assigner: GitHub_M
Reserved: 29.01.2026 Published: 03.03.2026 Updated: 03.03.2026

OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret value is rendered to the client in plaintext. These secret keys being leaked could result in arbitrary money movement or broad account takeover of payment gateway APIs. This vulnerability is fixed in 8.0.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CVSS Score: 9.6

Product Status

Vendor openemr
Product openemr
Versions
  • Version >= 5.0.2, < 8.0.0 is affected

References

Problem Types

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE