Intel

AIKIDO-2025-10085

solana-agent-kit is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

15

Low Risk

This Affects:

jssolana-agent-kit
1.3.6 - 1.4.4
Fixed in 1.4.5

TL;DR

Affected versions of this package may expose sensitive information in log files by logging the private key when the agent's keypair is loaded.

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

solana-agent-kit is vulnerable to Insertion of Sensitive Information into Log File in versions 1.3.6 - 1.4.4.

How to fix this

Upgrade solana-agent-kit to a patch version.