Intel

AIKIDO-2025-10146

@settlemint/asset-tokenization-kit is vulnerable to Log Injection

Log Injection Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 11, 2025

29

Low Risk

This Affects:

js@settlemint/asset-tokenization-kit
0.0.10 - 0.1.15
Fixed in 0.2.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are affected by improper input validation in error messages and user-controlled search strings, which can lead to injection attacks. Attackers can exploit this by injecting malicious input, such as special characters, into error logs or search queries. This issue could poison log files or manipulate application behavior, as mishandling backslashes in search queries regex sanitization may allow attackers to inject single quotes, potentially leading to SQL injection.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@settlemint/asset-tokenization-kit is vulnerable to Log Injection in versions 0.0.10 - 0.1.15.

How to fix this

Upgrade the @settlemint/asset-tokenization-kit library to the patch version.