Intel

AIKIDO-2025-10129

graphweaver is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 4, 2025

35

Low Risk

This Affects:

JSgraphweaver
0.1.18 - 2.12.1
Fixed in 2.12.2
Are you affected? Scan for Free

TL;DR

Affected versions of the package expose sensitive information in log files due to an insufficient mechanism for obfuscating sensitive argument values in authentication-related mutations. This issue affects multiple authentication methods, potentially leading to unauthorized access if log files are compromised.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

graphweaver is vulnerable to Insertion of Sensitive Information into Log File in versions 0.1.18 - 2.12.1.

How to fix this

Upgrade the graphweaver library to the patch version.