Intel

AIKIDO-2025-10097

@coinbase/wallet-sdk is vulnerable to Missing Encryption of Sensitive Data

Missing Encryption of Sensitive DataGHSA-8rgj-285w-qcq4 Published Feb 14, 2025

90

Critical Risk

This Affects:

js@coinbase/wallet-sdk
4.0.0 - 4.2.4
Fixed in 4.3.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package fail to encrypt sensitive data due to request signing occurring in an untrusted context. This can expose confidential information, potentially allowing attackers to intercept or manipulate signed requests.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@coinbase/wallet-sdk is vulnerable to Missing Encryption of Sensitive Data in versions 4.0.0 - 4.2.4.

How to fix this

Upgrade the @coinbase/wallet-sdk library to the patch version.